tm-v1-schema

Zero Trust Secure Access - Internet Access

Layer: Network

This documentation provides detailed information about all fields available for Zero Trust Secure Access - Internet Access.

Field Name Type Searchable General Field Description Example Products
act dynamic true - The actions taken to mitigate the event
  • log
  • isolate
  • terminate
  • not blocked
  • Block
  • No action
  • Reset
  • Pass
  • User Decision
  • Trend Vision One Container Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Cloud App Security
  • TippingPoint Security Management System
  • Endpoint Sensor
  • Trend Micro Web Security
  • Trend Micro Email Security
  • Trend Micro Deep Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • TXOne EdgeOne
  • Zero Trust Secure Access - Private Access
  • Email Sensor
  • Trend Vision One Mobile Security
  • Mobile Network Security
  • Agentless Vulnerability & Threat Detection
act string true - The action
  • Allow
  • Block
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
aggregatedCount string true - The number of aggregated events
  • 1
  • 2
  • 3
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • TippingPoint Security Management System
  • Trend Micro Web Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • TXOne StellarOne
  • Data Detection and Response
  • Trend Cloud One - Endpoint & Workload Security
application string true - The name of the requested application
  • HyperText Transfer Protocol
  • DoubleClick
  • The Secure HyperText Transfer Protocol
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Trend Micro Apex One as a Service
application string true - The name of the requested application
  • Facebook
  • wiki
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
authType string true - The authorization type
  • Cookie JWT
  • No Auth
Zero Trust Secure Access - Internet Access
authType string true - The authentication method
  • {'Cookie JWT': 'Authenticated by browser cookie with JWT token'}
  • {'Agent JWT': 'Authenticated by Secure Access Module with JWT token'}
  • {'IP': 'Authentication bypassed by private IP.'}
  • {'No Auth': 'No authentication.'}
Zero Trust Secure Access - Internet Access
clientIp dynamic true - The IP addresses of the source 10.10.10.10
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
clientIp string true
  • IPv4
  • IPv6
The endpoint IP address 10.10.10.10
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
clientProtocol string true - The client protocol HTTP/1.1 Zero Trust Secure Access - Internet Access
clientTls string true - The transport layer security of the client TLS 1.2 Zero Trust Secure Access - Internet Access
cloudAppCat string true - The category of the event in Cloud Reputation Service
  • All
  • Online Service
  • Application Suite
  • Business Intelligence and Analytics
  • Cloud Computing Platform
Zero Trust Secure Access - Internet Access
cloudAppCat string true - The category of the event in Cloud Reputation Service
  • All
  • Online Service
  • Application Suite
  • Business Intelligence and Analytics
  • Cloud Computing Platform
Zero Trust Secure Access - Internet Access
contentEncoding string true - The content encoding of the request or the response gzip Zero Trust Secure Access - Internet Access
detectionType string true - The detection type
  • 1
  • File
  • Process
  • net
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Web Security
  • Trend Micro Apex One as a Service
  • Trend Micro Cloud App Security
  • Trend Micro Deep Security
  • Trend Micro Email Security
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Zero Trust Secure Access - Private Access
  • Trend Vision One Container Security
detectionType string true - The traffic detection type
  • No matched Zero Trust Secure Access rule
  • Missing or invalid client certificate
  • Untrusted server certificate
  • Zero Trust Secure Access
  • HTTPS inspection exception
  • HTTPS inspection failure
  • HTTPS bypass at inspection failure
  • Approved URLs
  • Blocked URLs
  • Private IP address access
  • Web Reputation
  • URL Filtering
  • Restricted file type
  • Restricted MIME type
  • Restricted file extension type
  • Anti-malware scan
  • File scan exception
  • Predictive Machine Learning
  • Botnet
  • Application Control
  • Virtual Analyzer submission
  • Tenancy Restriction
  • Suspicious Object Blocked List
  • Data Loss Prevention
  • Ransomware
  • Risk Control
  • AI Service Risk Control
  • Non-compliant device
  • AI Service Access
  • AI Service Sensitive Data Prevention
  • AI Service Prompt Injection
  • AI Service Improper Answer
  • AI Service Malicious URL Answer
  • AI Service File Upload Detection
  • AI Service Rate Limiting
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
deviceGUID string true - The GUID of the agent which reported the detection
  • 00000000-0000-0000-0000-000000000000
  • 11111111-1111-1111-1111-111111111111
  • 22222222-2222-2222-2222-222222222222
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • TippingPoint Security Management System
  • Endpoint Sensor
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
deviceGUID string true - The non-endpoint object such as a network appliance 11111111-1111-1111-1111-111111111111
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
dst dynamic true
  • IPv4
  • IPv6
The destination IP 10.10.10.10
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Cloud One - Endpoint & Workload Security
  • TippingPoint Security Management System
  • Trend Micro Deep Security
  • Trend Cloud One - Network Security
  • Endpoint Sensor
  • Zero Trust Secure Access - Internet Access
  • TXOne EdgeOne
  • Zero Trust Secure Access - Private Access
  • Trend Vision One Container Security
  • Mobile Network Security
dst string true
  • IPv4
  • IPv6
The destination IP address (dstaddr) 10.10.10.10
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • XDR for Cloud - AWS VPC Flow Logs
  • azv
dstLocation string true - The destination country JP Zero Trust Secure Access - Internet Access
dstLocation string true - The destination country JP Zero Trust Secure Access - Internet Access
duration string true - The time it took the scanner to complete the scan, in milliseconds 1599465660123 Zero Trust Secure Access - Internet Access
e2eLatency string true - The end-to-end traffic latency time, in milliseconds 10000 Zero Trust Secure Access - Internet Access
endpointGUID string true EndpointID The GUID of the agent which reported the detection
  • ae4d64aa-f8b8-bb36-b265-f59272ed342f
  • 8fb979f6-1376-bed3-227f-f2886e66194e
  • ca2b3a7e-8415-c571-cc19-e45f69470026
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Endpoint Sensor
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Zero Trust Secure Access - Private Access
  • TXOne StellarOne
  • Trend Vision One Container Security
  • Data Detection and Response
endpointGuid string true EndpointID The device GUID
  • 11111111-1111-1111-1111-111111111111
  • DSP84573ULLJHM5GK2R7
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
endpointHostName string true EndpointName The endpoint hostname or node where the event was detected
  • 10.10.10.10 (swpos-aws-aza02) [i-0f0f0f0f0f0f0f0f0]
  • ip-10-10-10-10.us-west-1.compute.internal
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Security
  • Trend Micro Apex One as a Service
  • Endpoint Sensor
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Zero Trust Secure Access - Private Access
  • TXOne StellarOne
  • Trend Vision One Container Security
  • Agentless Vulnerability & Threat Detection
  • Data Detection and Response
endpointHostName string true EndpointName The host name of the device on which the event was detected
  • my_machine
  • jeremy-mbp
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
eventName string true - The event type
  • LOG_INSPECTION_EVENT
  • SECURITY_RISK_DETECTION
  • WEB_THREAT_DETECTION
  • LOG_INSPECTION_EVENT
  • MALWARE_DETECTION
  • PROCESS_ACTIVITY
  • WEB_POLICY_VIOLATION
  • DEEP_PACKET_INSPECTION_EVENT
  • INTEGRITY_MONITORING_EVENT
  • DISRUPTIVE_APPLICATION_DETECTION
  • PRODUCT_SUMMARY
  • PRODUCT_UPDATE
  • BEHAVIORAL_VIOLATION
  • FIREWALL_POLICY_VIOLATION
  • SUSPICIOUS_BEHAVIOUR_DETECTION
  • DENYLIST_CHANGE
  • MACHINE_LEARNING_DETECTION
  • DLP_VIOLATION
  • MALWARE_OUTBREAK_DETECTION
  • SENSITIVE_DATA_DETECTION
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • TippingPoint Security Management System
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Endpoint Sensor
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • TXOne EdgeOne
  • Zero Trust Secure Access - Private Access
  • TXOne StellarOne
  • Email Sensor
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
  • Trend Vision One Mobile Security
  • Mobile Network Security
  • Data Detection and Response
eventName string true - The name of the log event
  • SWG_ACTIVITY_LOG
  • FIREWALL_ACTIVITY_LOG
  • VPC_ACTIVITY_LOG
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • XDR for Cloud - AWS VPC Flow Logs
  • azv
eventSubName string true - The event type sub-name
  • IPS Detection
  • Personal Firewall
  • Attack Discovery
  • Trend Micro Apex One as a Service
  • Trend Micro Cloud App Security
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Email Security
  • Endpoint Sensor
  • Zero Trust Secure Access - Internet Access
  • Agentless Vulnerability & Threat Detection
eventSubName string true - The Zero Trust Secure Access - Internet Access cloud app action or the Palo Alto Networks firewall log sub-type
  • OneDrive download file
  • start
  • end
  • drop
  • deny
Zero Trust Secure Access - Internet Access
eventTime real true - The time the agent or product detected the event 1657135700000
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • XDR for Cloud - AWS VPC Flow Logs
  • azv
failedHTTPSInspection bool true - HTTPS traffic inspection failure True Zero Trust Secure Access - Internet Access
fileHash string true FileSHA1 The SHA-1 of the file that triggered the rule or policy
  • DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
  • 89CE26EAD139D52B8A6B61BFFC6AF89AF246580F
  • 3AD1F4E7CAA11E5199EE80B8983677ADDD065450
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Deep Security
  • Trend Micro Apex One as a Service
  • Zero Trust Secure Access - Internet Access
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
  • Data Detection and Response
fileHash string true FileSHA1 The SHA-1 of the file that violated the policy 1e15bf99022a9164708cebb3eace8fd61ad45cba
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
fileHashSha256 string true FileSHA2 The SHA-256 of the file (fileName)
  • 6A6EB2D717CEA041B4444193B45EDFB6CA1287518203B7230B3C4B8FFB031EAB
  • BFF703FF836196644586014DA13A097C2EE9A08E4D596DFB7C8E0F685FE01294
  • 12327F460AC9CBBC34D39EB3CF89C7FECCA37F08773A04566840F73F6ECC4104
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Zero Trust Secure Access - Internet Access
  • Trend Cloud One - Endpoint & Workload Security
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
  • Trend Vision One Container Security
fileHashSha256 string true FileSHA2 The SHA-256 of the file that violated the policy ba9edecdd09de1307714564c24409bd25508e22fe11c768053a08f173f263e93
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
fileName dynamic true FileName The file name
  • spoolss
  • hosts
  • svcrestarttask
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Zero Trust Secure Access - Internet Access
  • TXOne StellarOne
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
fileName string true
  • FileName
  • FileFullPath
The name of the file that violated the policy word.doc
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
fileSize string true - The file size of the suspicious file
  • 0
  • 1255856
  • 1237880
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Apex One as a Service
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
fileSize string true - The size of the file that is violating the policy 12134
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
fileType string true - The file type of the suspicious file
  • EXE
  • LNK
  • MIME
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Zero Trust Secure Access - Internet Access
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
  • Trend Vision One Container Security
fileType string true - The type of file which is violating the policy Microsoft Words
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
isPrivateApp bool true - Whether the requested application is private
  • True
Zero Trust Secure Access - Internet Access
isPrivateApp bool true - Whether the requested application is private
  • True
Zero Trust Secure Access - Internet Access
logKey string true - The unique key of the event
  • 123e4567-e89b-12d3-a456-426614174000
  • 987f6543-21ba-43cd-9e8f-123456789abc
  • 456789ab-cdef-1234-5678-9abcdef01234
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • TippingPoint Security Management System
  • Endpoint Sensor
  • Trend Micro Web Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
malName string true - The name of the detected malware - Zero Trust Secure Access - Internet Access
mimeType string true - The MIME type or content type of the response body
  • application/octet-stream
  • application/json; charset=utf-8
  • application/json
Zero Trust Secure Access - Internet Access
mimeType string true - The MIME type or content type of the response body text/html
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
osName string true - The host OS name
  • Linux
  • windows 10.0.22000
  • windows 10.0.19044
  • windows 10.0.19043
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Zero Trust Secure Access - Private Access
  • Data Detection and Response
  • Agentless Vulnerability & Threat Detection
osName string true - The host operating system name
  • Windows 10
  • macos 12.1
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
pname string true - The internal product ID
  • Trend Micro Deep Security
  • Deep Discovery Inspector
  • Apex One
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • TippingPoint Security Management System
  • Endpoint Sensor
  • Trend Micro Web Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Trend Vision One Container Security
  • Email Sensor
pname string true - The product name
  • Secure Web Gateway
  • XDR for Cloud - AWS VPC Flow Logs
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • XDR for Cloud - AWS VPC Flow Logs
  • azv
policyName string true - The name of the triggered policy
  • Steelcase
  • Cabot
  • Tigre - Medium Policy
  • apiPostedPolicy
  • Trend Micro Apex One as a Service
  • Trend Micro Cloud App Security
  • Trend Micro Web Security
  • Trend Micro Email Security
  • Zero Trust Secure Access - Internet Access
  • TXOne EdgeOne
  • Trend Vision One Container Security
  • Mobile Network Security
policyTemplate dynamic true - The one-to-many data structure
  • policyName:Monitoreo All Files, template:Managed - All files
  • policyName:HSS DLP, template:All File Extension
  • India: Mobile Numbers
  • Trend Micro Apex One as a Service
  • Trend Micro Cloud App Security
  • Zero Trust Secure Access - Internet Access
policyTemplate dynamic true - The Data Loss Prevention template name Australia, New Zealand: Healthcare Template,Germany: Banking and Financial Information Zero Trust Secure Access - Internet Access
policyUuid string true - The UUID of the cloud access or risk control policy, or the hard-coded string that indicates the rule of the global blocked/approved URL list
  • 7937cb0b-e598-4c8f-a50f-65c32905ba3a
  • C!7c4433e3-5b2c-449f-b66e-ccaac006b6f1
  • 8d265639-7202-4455-b640-48683aa2b57d
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
principalName string true - The user principal name used to sign in to the proxy sample_email@trendmicro.com
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Cloud App Security
  • Zero Trust Secure Access - Private Access
principalName string true UserAccount The User Principal Name sample_email@trendmicro.com
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
profile string true - The name of the triggered Threat Protection template or Data Loss Prevention profile
  • Primary Protection Rule
  • Multibak Scaner Threat
  • default
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
profile string true - The name of the triggered Threat Protection template or Data Loss Prevention profile triggered - Zero Trust Secure Access - Internet Access
pver string true - The product version
  • 20.0.0.4726
  • 20.0.0.4416
  • 6.2.1125
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Deep Security
  • Trend Micro Apex One as a Service
  • TippingPoint Security Management System
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • Trend Vision One Mobile Security
  • Trend Vision One Container Security
  • File Security
  • File Security Storage
  • Agentless Vulnerability & Threat Detection
pver string true - The product version 1.0 Zero Trust Secure Access - Internet Access
request string true URL The notable URLs
  • http://example.page.com/canonical.html
  • http://10.10.10.10
  • https://drive.google.com/
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • TippingPoint Security Management System
  • Trend Cloud One - Endpoint & Workload Security
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Cloud App Security
  • Trend Cloud One - Network Security
  • Trend Micro Email Security
  • Trend Micro Deep Security
  • Trend Vision One Mobile Security
  • Zero Trust Secure Access - Private Access
request string true URL The destination URL that the user is accessing
  • https://google.com/
  • https://api/example/v1/testit
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
requestBase string true
  • DomainName
  • HostDomain
The domain of the request URL
  • weather.service.msn.com
  • test.domain.com
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
requestBase string true
  • DomainName
  • HostDomain
The URL domain
  • www.facebook.com
  • gary.webserver64.com
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
requestMethod string true - The network protocol request method POST
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
requestMimeType string true - The type of request content application/json; charset=utf-8
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
requestSize string true - The request length 1324 Zero Trust Secure Access - Internet Access
responseSize string true - The response length 1324 Zero Trust Secure Access - Internet Access
rt string false - The Unix time of the log generation 1656324260000
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • TippingPoint Security Management System
  • Endpoint Sensor
  • Trend Micro Web Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • Email Sensor
rt string false - The UTC timestamp 1599465660
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
ruleName string true - The name of the triggered cloud access rule
  • ETL_Access Rules_Web_Host
  • block_wiki_for_guest
  • BlockHighRiskTCPPortsFromInternet
  • unspecified
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • azv
score int false - The WRS score 81 Zero Trust Secure Access - Internet Access
sender string true - The roaming users or the gateway where the web traffic passed
  • test user
  • VE C&W - 10.10.10.10
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
sender string true - The Zero Trust Internet Access gateway location
  • {'Public/Home network': 'The default cloud gateway.'}
  • {'Anything else': 'The pre-defined location name of cloud gateway or on-premises gateway.'}
Zero Trust Secure Access - Internet Access
serverProtocol string true - The version of the HTTP protocol between the Service Gateway and server/website HTTP/1.1
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
serverRespTime string true - The time the server took to respond to the request, in milliseconds 1599465660123 Zero Trust Secure Access - Internet Access
serverTls string true - The TLS version between the Service Gateway and server/website TLS 1.2
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
src dynamic true
  • IPv4
  • IPv6
The source IP 10.10.10.10
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Apex One as a Service
  • Trend Cloud One - Endpoint & Workload Security
  • TippingPoint Security Management System
  • Trend Micro Deep Security
  • Trend Cloud One - Network Security
  • Endpoint Sensor
  • Zero Trust Secure Access - Internet Access
  • TXOne EdgeOne
  • Zero Trust Secure Access - Private Access
  • Trend Vision One Container Security
  • Mobile Network Security
src string true
  • IPv4
  • IPv6
The source IP address (srcaddr) 10.10.10.10
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
  • XDR for Cloud - AWS VPC Flow Logs
  • azv
srcLocation string true - The source country JP Zero Trust Secure Access - Internet Access
srcLocation string true - The source country JP Zero Trust Secure Access - Internet Access
suid string true UserAccount User name or mailbox
  • root
  • US EXAMPLE\TEST
  • sample_email@trendmicro.com
  • Trend Cloud One - Endpoint & Workload Security
  • Trend Micro Cloud App Security
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Web Security
  • Trend Micro Deep Security
  • Trend Cloud One - Network Security
  • Zero Trust Secure Access - Internet Access
suid string true UserAccount The user name or IP address (IPv4)
  • Sample User Name
  • 10.10.10.10
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
tlsJA3Fingerprint string true - The JA3 fingerprint -
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
trafficType string true - The Zero Trust Internet Access gateway service mode
  • {'Proxy': 'Zero Trust Internet Access On-Premises Gateway with forward proxy mode configured'}
  • {'Forward': 'Zero Trust Internet Access On-Premises Gateway with forward proxy mode and port forwarding configured'}
  • {'ICAP': 'Zero Trust Internet Access On-Premises Gateway with ICAP configured'}
  • {'Reverse': 'Zero Trust Internet Access On-Premises Gateway with reverse proxy mode configured'}
  • {'Proxy (xx)': 'Cloud Gateway in xx PoP with forward proxy mode'}
  • {'Forward (xx)': 'Cloud Gateway in xx PoP with forward proxy mode for port forwarding'}
Zero Trust Secure Access - Internet Access
urlCat dynamic true - The requested URL category
  • Untested
  • 158
  • Web Advertisement
  • Trend Micro Deep Discovery Inspector
  • Network Sensor
  • Trend Micro Web Security
  • Trend Micro Apex One as a Service
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Cloud App Security
  • Trend Vision One Mobile Security
  • Trend Cloud One - Endpoint & Workload Security
urlCat string false - The URL category Social Networking Zero Trust Secure Access - Internet Access
userAgent string false - The user agent or the agent through which the request was made
  • Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0)
  • Chrome/74.0.3729.108 Safari/537.36
  • Zero Trust Secure Access - Internet Access
  • Zero Trust Secure Access - Private Access
userDepartment string true - User department
  • Operations
  • BANCA CONSTRUCCION
  • CONTACT CENTER
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
userDepartment string true - The user department request method Sales Zero Trust Secure Access - Internet Access
userDomain string true
  • EndpointName
  • DomainName
  • AccountDomain
The user domain
  • example.com.pa
  • DOMAIN
  • Trend Micro Apex One as a Service
  • Trend Micro Web Security
  • Zero Trust Secure Access - Internet Access
userDomain string true
  • DomainName
  • AccountDomain
Active directory domain, domain of username for logging in TMAS adminportal adminportal trendmicro.com
  • Zero Trust Secure Access - Internet Access
  • Trend Micro Deep Discovery Inspector
  • Network Sensor

Field Statistics


Generated by XDR Common Schema Public Doc Generator V2