act |
dynamic |
true |
- |
The actions taken to mitigate the event |
- log
- isolate
- terminate
- not blocked
- Block
- No action
- Reset
- Pass
- User Decision
|
- Trend Vision One Container Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Cloud App Security
- TippingPoint Security Management System
- Endpoint Sensor
- Trend Micro Web Security
- Trend Micro Email Security
- Trend Micro Deep Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- TXOne EdgeOne
- Zero Trust Secure Access - Private Access
- Email Sensor
- Trend Vision One Mobile Security
- Mobile Network Security
- Agentless Vulnerability & Threat Detection
|
act |
string |
true |
- |
The action |
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
aggregatedCount |
string |
true |
- |
The number of aggregated events |
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- TippingPoint Security Management System
- Trend Micro Web Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- TXOne StellarOne
- Data Detection and Response
- Trend Cloud One - Endpoint & Workload Security
|
application |
string |
true |
- |
The name of the requested application |
- HyperText Transfer Protocol
- DoubleClick
- The Secure HyperText Transfer Protocol
|
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Trend Micro Apex One as a Service
|
application |
string |
true |
- |
The name of the requested application |
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
authType |
string |
true |
- |
The authorization type |
|
Zero Trust Secure Access - Internet Access |
authType |
string |
true |
- |
The authentication method |
- {'Cookie JWT': 'Authenticated by browser cookie with JWT token'}
- {'Agent JWT': 'Authenticated by Secure Access Module with JWT token'}
- {'IP': 'Authentication bypassed by private IP.'}
- {'No Auth': 'No authentication.'}
|
Zero Trust Secure Access - Internet Access |
clientIp |
dynamic |
true |
- |
The IP addresses of the source |
10.10.10.10 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
clientIp |
string |
true |
|
The endpoint IP address |
10.10.10.10 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
clientProtocol |
string |
true |
- |
The client protocol |
HTTP/1.1 |
Zero Trust Secure Access - Internet Access |
clientTls |
string |
true |
- |
The transport layer security of the client |
TLS 1.2 |
Zero Trust Secure Access - Internet Access |
cloudAppCat |
string |
true |
- |
The category of the event in Cloud Reputation Service |
- All
- Online Service
- Application Suite
- Business Intelligence and Analytics
- Cloud Computing Platform
|
Zero Trust Secure Access - Internet Access |
cloudAppCat |
string |
true |
- |
The category of the event in Cloud Reputation Service |
- All
- Online Service
- Application Suite
- Business Intelligence and Analytics
- Cloud Computing Platform
|
Zero Trust Secure Access - Internet Access |
contentEncoding |
string |
true |
- |
The content encoding of the request or the response |
gzip |
Zero Trust Secure Access - Internet Access |
detectionType |
string |
true |
- |
The detection type |
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Web Security
- Trend Micro Apex One as a Service
- Trend Micro Cloud App Security
- Trend Micro Deep Security
- Trend Micro Email Security
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Zero Trust Secure Access - Private Access
- Trend Vision One Container Security
|
detectionType |
string |
true |
- |
The traffic detection type |
- No matched Zero Trust Secure Access rule
- Missing or invalid client certificate
- Untrusted server certificate
- Zero Trust Secure Access
- HTTPS inspection exception
- HTTPS inspection failure
- HTTPS bypass at inspection failure
- Approved URLs
- Blocked URLs
- Private IP address access
- Web Reputation
- URL Filtering
- Restricted file type
- Restricted MIME type
- Restricted file extension type
- Anti-malware scan
- File scan exception
- Predictive Machine Learning
- Botnet
- Application Control
- Virtual Analyzer submission
- Tenancy Restriction
- Suspicious Object Blocked List
- Data Loss Prevention
- Ransomware
- Risk Control
- AI Service Risk Control
- Non-compliant device
- AI Service Access
- AI Service Sensitive Data Prevention
- AI Service Prompt Injection
- AI Service Improper Answer
- AI Service Malicious URL Answer
- AI Service File Upload Detection
- AI Service Rate Limiting
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
deviceGUID |
string |
true |
- |
The GUID of the agent which reported the detection |
- 00000000-0000-0000-0000-000000000000
- 11111111-1111-1111-1111-111111111111
- 22222222-2222-2222-2222-222222222222
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- TippingPoint Security Management System
- Endpoint Sensor
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
|
deviceGUID |
string |
true |
- |
The non-endpoint object such as a network appliance |
11111111-1111-1111-1111-111111111111 |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
dst |
dynamic |
true |
|
The destination IP |
10.10.10.10 |
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Cloud One - Endpoint & Workload Security
- TippingPoint Security Management System
- Trend Micro Deep Security
- Trend Cloud One - Network Security
- Endpoint Sensor
- Zero Trust Secure Access - Internet Access
- TXOne EdgeOne
- Zero Trust Secure Access - Private Access
- Trend Vision One Container Security
- Mobile Network Security
|
dst |
string |
true |
|
The destination IP address (dstaddr) |
10.10.10.10 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- XDR for Cloud - AWS VPC Flow Logs
- azv
|
dstLocation |
string |
true |
- |
The destination country |
JP |
Zero Trust Secure Access - Internet Access |
dstLocation |
string |
true |
- |
The destination country |
JP |
Zero Trust Secure Access - Internet Access |
duration |
string |
true |
- |
The time it took the scanner to complete the scan, in milliseconds |
1599465660123 |
Zero Trust Secure Access - Internet Access |
e2eLatency |
string |
true |
- |
The end-to-end traffic latency time, in milliseconds |
10000 |
Zero Trust Secure Access - Internet Access |
endpointGUID |
string |
true |
EndpointID |
The GUID of the agent which reported the detection |
- ae4d64aa-f8b8-bb36-b265-f59272ed342f
- 8fb979f6-1376-bed3-227f-f2886e66194e
- ca2b3a7e-8415-c571-cc19-e45f69470026
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- Endpoint Sensor
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Zero Trust Secure Access - Private Access
- TXOne StellarOne
- Trend Vision One Container Security
- Data Detection and Response
|
endpointGuid |
string |
true |
EndpointID |
The device GUID |
- 11111111-1111-1111-1111-111111111111
- DSP84573ULLJHM5GK2R7
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
endpointHostName |
string |
true |
EndpointName |
The endpoint hostname or node where the event was detected |
- 10.10.10.10 (swpos-aws-aza02) [i-0f0f0f0f0f0f0f0f0]
- ip-10-10-10-10.us-west-1.compute.internal
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Security
- Trend Micro Apex One as a Service
- Endpoint Sensor
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Zero Trust Secure Access - Private Access
- TXOne StellarOne
- Trend Vision One Container Security
- Agentless Vulnerability & Threat Detection
- Data Detection and Response
|
endpointHostName |
string |
true |
EndpointName |
The host name of the device on which the event was detected |
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
eventName |
string |
true |
- |
The event type |
- LOG_INSPECTION_EVENT
- SECURITY_RISK_DETECTION
- WEB_THREAT_DETECTION
- LOG_INSPECTION_EVENT
- MALWARE_DETECTION
- PROCESS_ACTIVITY
- WEB_POLICY_VIOLATION
- DEEP_PACKET_INSPECTION_EVENT
- INTEGRITY_MONITORING_EVENT
- DISRUPTIVE_APPLICATION_DETECTION
- PRODUCT_SUMMARY
- PRODUCT_UPDATE
- BEHAVIORAL_VIOLATION
- FIREWALL_POLICY_VIOLATION
- SUSPICIOUS_BEHAVIOUR_DETECTION
- DENYLIST_CHANGE
- MACHINE_LEARNING_DETECTION
- DLP_VIOLATION
- MALWARE_OUTBREAK_DETECTION
- SENSITIVE_DATA_DETECTION
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- TippingPoint Security Management System
- Trend Micro Cloud App Security
- Trend Micro Email Security
- Endpoint Sensor
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- TXOne EdgeOne
- Zero Trust Secure Access - Private Access
- TXOne StellarOne
- Email Sensor
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
- Trend Vision One Mobile Security
- Mobile Network Security
- Data Detection and Response
|
eventName |
string |
true |
- |
The name of the log event |
- SWG_ACTIVITY_LOG
- FIREWALL_ACTIVITY_LOG
- VPC_ACTIVITY_LOG
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
- XDR for Cloud - AWS VPC Flow Logs
- azv
|
eventSubName |
string |
true |
- |
The event type sub-name |
- IPS Detection
- Personal Firewall
- Attack Discovery
|
- Trend Micro Apex One as a Service
- Trend Micro Cloud App Security
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Email Security
- Endpoint Sensor
- Zero Trust Secure Access - Internet Access
- Agentless Vulnerability & Threat Detection
|
eventSubName |
string |
true |
- |
The Zero Trust Secure Access - Internet Access cloud app action or the Palo Alto Networks firewall log sub-type |
- OneDrive download file
- start
- end
- drop
- deny
|
Zero Trust Secure Access - Internet Access |
eventTime |
real |
true |
- |
The time the agent or product detected the event |
1657135700000 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
- XDR for Cloud - AWS VPC Flow Logs
- azv
|
failedHTTPSInspection |
bool |
true |
- |
HTTPS traffic inspection failure |
True |
Zero Trust Secure Access - Internet Access |
fileHash |
string |
true |
FileSHA1 |
The SHA-1 of the file that triggered the rule or policy |
- DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
- 89CE26EAD139D52B8A6B61BFFC6AF89AF246580F
- 3AD1F4E7CAA11E5199EE80B8983677ADDD065450
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Deep Security
- Trend Micro Apex One as a Service
- Zero Trust Secure Access - Internet Access
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
- Data Detection and Response
|
fileHash |
string |
true |
FileSHA1 |
The SHA-1 of the file that violated the policy |
1e15bf99022a9164708cebb3eace8fd61ad45cba |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
fileHashSha256 |
string |
true |
FileSHA2 |
The SHA-256 of the file (fileName) |
- 6A6EB2D717CEA041B4444193B45EDFB6CA1287518203B7230B3C4B8FFB031EAB
- BFF703FF836196644586014DA13A097C2EE9A08E4D596DFB7C8E0F685FE01294
- 12327F460AC9CBBC34D39EB3CF89C7FECCA37F08773A04566840F73F6ECC4104
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Zero Trust Secure Access - Internet Access
- Trend Cloud One - Endpoint & Workload Security
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
- Trend Vision One Container Security
|
fileHashSha256 |
string |
true |
FileSHA2 |
The SHA-256 of the file that violated the policy |
ba9edecdd09de1307714564c24409bd25508e22fe11c768053a08f173f263e93 |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
fileName |
dynamic |
true |
FileName |
The file name |
- spoolss
- hosts
- svcrestarttask
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- Zero Trust Secure Access - Internet Access
- TXOne StellarOne
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
|
fileName |
string |
true |
|
The name of the file that violated the policy |
word.doc |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
fileSize |
string |
true |
- |
The file size of the suspicious file |
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Zero Trust Secure Access - Internet Access
- Trend Micro Apex One as a Service
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
|
fileSize |
string |
true |
- |
The size of the file that is violating the policy |
12134 |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
fileType |
string |
true |
- |
The file type of the suspicious file |
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Zero Trust Secure Access - Internet Access
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
- Trend Vision One Container Security
|
fileType |
string |
true |
- |
The type of file which is violating the policy |
Microsoft Words |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
isPrivateApp |
bool |
true |
- |
Whether the requested application is private |
|
Zero Trust Secure Access - Internet Access |
isPrivateApp |
bool |
true |
- |
Whether the requested application is private |
|
Zero Trust Secure Access - Internet Access |
logKey |
string |
true |
- |
The unique key of the event |
- 123e4567-e89b-12d3-a456-426614174000
- 987f6543-21ba-43cd-9e8f-123456789abc
- 456789ab-cdef-1234-5678-9abcdef01234
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- Trend Micro Cloud App Security
- Trend Micro Email Security
- TippingPoint Security Management System
- Endpoint Sensor
- Trend Micro Web Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
|
malName |
string |
true |
- |
The name of the detected malware |
- |
Zero Trust Secure Access - Internet Access |
mimeType |
string |
true |
- |
The MIME type or content type of the response body |
- application/octet-stream
- application/json; charset=utf-8
- application/json
|
Zero Trust Secure Access - Internet Access |
mimeType |
string |
true |
- |
The MIME type or content type of the response body |
text/html |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
osName |
string |
true |
- |
The host OS name |
- Linux
- windows 10.0.22000
- windows 10.0.19044
- windows 10.0.19043
|
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Zero Trust Secure Access - Private Access
- Data Detection and Response
- Agentless Vulnerability & Threat Detection
|
osName |
string |
true |
- |
The host operating system name |
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
pname |
string |
true |
- |
The internal product ID |
- Trend Micro Deep Security
- Deep Discovery Inspector
- Apex One
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- Trend Micro Cloud App Security
- Trend Micro Email Security
- TippingPoint Security Management System
- Endpoint Sensor
- Trend Micro Web Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Trend Vision One Container Security
- Email Sensor
|
pname |
string |
true |
- |
The product name |
- Secure Web Gateway
- XDR for Cloud - AWS VPC Flow Logs
|
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
- XDR for Cloud - AWS VPC Flow Logs
- azv
|
policyName |
string |
true |
- |
The name of the triggered policy |
- Steelcase
- Cabot
- Tigre - Medium Policy
- apiPostedPolicy
|
- Trend Micro Apex One as a Service
- Trend Micro Cloud App Security
- Trend Micro Web Security
- Trend Micro Email Security
- Zero Trust Secure Access - Internet Access
- TXOne EdgeOne
- Trend Vision One Container Security
- Mobile Network Security
|
policyTemplate |
dynamic |
true |
- |
The one-to-many data structure |
- policyName:Monitoreo All Files, template:Managed - All files
- policyName:HSS DLP, template:All File Extension
- India: Mobile Numbers
|
- Trend Micro Apex One as a Service
- Trend Micro Cloud App Security
- Zero Trust Secure Access - Internet Access
|
policyTemplate |
dynamic |
true |
- |
The Data Loss Prevention template name |
Australia, New Zealand: Healthcare Template,Germany: Banking and Financial Information |
Zero Trust Secure Access - Internet Access |
policyUuid |
string |
true |
- |
The UUID of the cloud access or risk control policy, or the hard-coded string that indicates the rule of the global blocked/approved URL list |
- 7937cb0b-e598-4c8f-a50f-65c32905ba3a
- C!7c4433e3-5b2c-449f-b66e-ccaac006b6f1
- 8d265639-7202-4455-b640-48683aa2b57d
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
principalName |
string |
true |
- |
The user principal name used to sign in to the proxy |
sample_email@trendmicro.com |
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
- Trend Micro Cloud App Security
- Zero Trust Secure Access - Private Access
|
principalName |
string |
true |
UserAccount |
The User Principal Name |
sample_email@trendmicro.com |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
profile |
string |
true |
- |
The name of the triggered Threat Protection template or Data Loss Prevention profile |
- Primary Protection Rule
- Multibak Scaner Threat
- default
|
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
|
profile |
string |
true |
- |
The name of the triggered Threat Protection template or Data Loss Prevention profile triggered |
- |
Zero Trust Secure Access - Internet Access |
pver |
string |
true |
- |
The product version |
- 20.0.0.4726
- 20.0.0.4416
- 6.2.1125
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Deep Security
- Trend Micro Apex One as a Service
- TippingPoint Security Management System
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- Trend Vision One Mobile Security
- Trend Vision One Container Security
- File Security
- File Security Storage
- Agentless Vulnerability & Threat Detection
|
pver |
string |
true |
- |
The product version |
1.0 |
Zero Trust Secure Access - Internet Access |
request |
string |
true |
URL |
The notable URLs |
- http://example.page.com/canonical.html
- http://10.10.10.10
- https://drive.google.com/
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- TippingPoint Security Management System
- Trend Cloud One - Endpoint & Workload Security
- Zero Trust Secure Access - Internet Access
- Trend Micro Cloud App Security
- Trend Cloud One - Network Security
- Trend Micro Email Security
- Trend Micro Deep Security
- Trend Vision One Mobile Security
- Zero Trust Secure Access - Private Access
|
request |
string |
true |
URL |
The destination URL that the user is accessing |
- https://google.com/
- https://api/example/v1/testit
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
requestBase |
string |
true |
|
The domain of the request URL |
- weather.service.msn.com
- test.domain.com
|
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
requestBase |
string |
true |
|
The URL domain |
- www.facebook.com
- gary.webserver64.com
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
requestMethod |
string |
true |
- |
The network protocol request method |
POST |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
requestMimeType |
string |
true |
- |
The type of request content |
application/json; charset=utf-8 |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
requestSize |
string |
true |
- |
The request length |
1324 |
Zero Trust Secure Access - Internet Access |
responseSize |
string |
true |
- |
The response length |
1324 |
Zero Trust Secure Access - Internet Access |
rt |
string |
false |
- |
The Unix time of the log generation |
1656324260000 |
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Micro Deep Security
- Trend Micro Cloud App Security
- Trend Micro Email Security
- TippingPoint Security Management System
- Endpoint Sensor
- Trend Micro Web Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- Email Sensor
|
rt |
string |
false |
- |
The UTC timestamp |
1599465660 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
ruleName |
string |
true |
- |
The name of the triggered cloud access rule |
- ETL_Access Rules_Web_Host
- block_wiki_for_guest
- BlockHighRiskTCPPortsFromInternet
- unspecified
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- azv
|
score |
int |
false |
- |
The WRS score |
81 |
Zero Trust Secure Access - Internet Access |
sender |
string |
true |
- |
The roaming users or the gateway where the web traffic passed |
- test user
- VE C&W - 10.10.10.10
|
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
|
sender |
string |
true |
- |
The Zero Trust Internet Access gateway location |
- {'Public/Home network': 'The default cloud gateway.'}
- {'Anything else': 'The pre-defined location name of cloud gateway or on-premises gateway.'}
|
Zero Trust Secure Access - Internet Access |
serverProtocol |
string |
true |
- |
The version of the HTTP protocol between the Service Gateway and server/website |
HTTP/1.1 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
serverRespTime |
string |
true |
- |
The time the server took to respond to the request, in milliseconds |
1599465660123 |
Zero Trust Secure Access - Internet Access |
serverTls |
string |
true |
- |
The TLS version between the Service Gateway and server/website |
TLS 1.2 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
src |
dynamic |
true |
|
The source IP |
10.10.10.10 |
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Apex One as a Service
- Trend Cloud One - Endpoint & Workload Security
- TippingPoint Security Management System
- Trend Micro Deep Security
- Trend Cloud One - Network Security
- Endpoint Sensor
- Zero Trust Secure Access - Internet Access
- TXOne EdgeOne
- Zero Trust Secure Access - Private Access
- Trend Vision One Container Security
- Mobile Network Security
|
src |
string |
true |
|
The source IP address (srcaddr) |
10.10.10.10 |
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
- XDR for Cloud - AWS VPC Flow Logs
- azv
|
srcLocation |
string |
true |
- |
The source country |
JP |
Zero Trust Secure Access - Internet Access |
srcLocation |
string |
true |
- |
The source country |
JP |
Zero Trust Secure Access - Internet Access |
suid |
string |
true |
UserAccount |
User name or mailbox |
- root
- US EXAMPLE\TEST
- sample_email@trendmicro.com
|
- Trend Cloud One - Endpoint & Workload Security
- Trend Micro Cloud App Security
- Trend Micro Apex One as a Service
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Web Security
- Trend Micro Deep Security
- Trend Cloud One - Network Security
- Zero Trust Secure Access - Internet Access
|
suid |
string |
true |
UserAccount |
The user name or IP address (IPv4) |
- Sample User Name
- 10.10.10.10
|
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
tlsJA3Fingerprint |
string |
true |
- |
The JA3 fingerprint |
- |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|
trafficType |
string |
true |
- |
The Zero Trust Internet Access gateway service mode |
- {'Proxy': 'Zero Trust Internet Access On-Premises Gateway with forward proxy mode configured'}
- {'Forward': 'Zero Trust Internet Access On-Premises Gateway with forward proxy mode and port forwarding configured'}
- {'ICAP': 'Zero Trust Internet Access On-Premises Gateway with ICAP configured'}
- {'Reverse': 'Zero Trust Internet Access On-Premises Gateway with reverse proxy mode configured'}
- {'Proxy (xx)': 'Cloud Gateway in xx PoP with forward proxy mode'}
- {'Forward (xx)': 'Cloud Gateway in xx PoP with forward proxy mode for port forwarding'}
|
Zero Trust Secure Access - Internet Access |
urlCat |
dynamic |
true |
- |
The requested URL category |
- Untested
- 158
- Web Advertisement
|
- Trend Micro Deep Discovery Inspector
- Network Sensor
- Trend Micro Web Security
- Trend Micro Apex One as a Service
- Zero Trust Secure Access - Internet Access
- Trend Micro Cloud App Security
- Trend Vision One Mobile Security
- Trend Cloud One - Endpoint & Workload Security
|
urlCat |
string |
false |
- |
The URL category |
Social Networking |
Zero Trust Secure Access - Internet Access |
userAgent |
string |
false |
- |
The user agent or the agent through which the request was made |
- Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0)
- Chrome/74.0.3729.108 Safari/537.36
|
- Zero Trust Secure Access - Internet Access
- Zero Trust Secure Access - Private Access
|
userDepartment |
string |
true |
- |
User department |
- Operations
- BANCA CONSTRUCCION
- CONTACT CENTER
|
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
|
userDepartment |
string |
true |
- |
The user department request method |
Sales |
Zero Trust Secure Access - Internet Access |
userDomain |
string |
true |
- EndpointName
- DomainName
- AccountDomain
|
The user domain |
|
- Trend Micro Apex One as a Service
- Trend Micro Web Security
- Zero Trust Secure Access - Internet Access
|
userDomain |
string |
true |
|
Active directory domain, domain of username for logging in TMAS adminportal adminportal |
trendmicro.com |
- Zero Trust Secure Access - Internet Access
- Trend Micro Deep Discovery Inspector
- Network Sensor
|