Skip to content

SonicWall SMA 1000 Series

Overview

SonicWall Secure Mobile Access 1000 Series logs are structured text-based records (mostly syslog-like and HTTP access formats, with XML exports) that capture timestamped system, administrative, access, tunnel, flow, web proxy, unregistered device, and WorkPlace events for monitoring, auditing, and incident analysis.

  • Vendor: SonicWall
  • Supported environment: On prem
  • Version compatibility: 12.5
  • Detection based on: Telemetry
  • Supported application or feature: DNS records

Configure

This setup guide will show you how to forward your SonicWall SMA 1000 Series logs to Sekoia.io by means of a syslog transport channel.

Prerequisites

  • Have an internal log concentrator (Rsyslog).

Enable Syslog forwarding for SonicWall SMA 1000 Series

  1. Log in the SonicWall SMA Appliance Management Console.
  2. Go to Monitoring > Logging > Configure Logging.
  3. In the Services Log Level section, define the severity level of log messages.
  4. In the Syslog Configuration section, type the IP address and the port of your log concentrator as primary syslog server (Server #1).

    SonicWall SMA 1000 Series settings

  5. Click Save to save your logging settings.

Create the intake

Go to the intake page and create a new intake from the SonicWall SMA 1000 Series format.

Forward logs to Sekoia.io

Please consult the Syslog Forwarding documentation to forward these logs to Sekoia.io.

Raw Events Samples

In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.

127.0.0.1 - admin [25/Jul/2025:05:30:52 -0700] "GET /Console/PendingChanges HTTP/1.1" 200 308
198.51.100.10 - - [01/Jul/2026:15:53:26 +0000] "POST /j_security_check HTTP/1.1" 303 0
Info 6/3/2025 00:31:02 admin Applied configuration changes
2025-07-25T12:31:06+00:00 AMC@gateway01.example.com local4.info AMC: 2025-07-25 12:31:06 +0000 INFO com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2 - Clearing traffic optimizer configuration
2026-07-01 15:53:26 +0000 INFO    [admin]: Login succeeded - Address=198.51.100.10
pam_unix(cron:session): session closed for user root
2026-07-02 14:33:15 +0000 INFO    [admin]: Adding user group - Name=grp4
2026-07-02 14:48:12 +0000 ERROR     com.aventail.mgmt.jetty.JettyServer - SSL handshake failed: Closed during handshake (198.51.100.10:40236)
2026-07-02 14:52:48 +0000 INFO    [admin]: Added address pool - ID=ID1111111111111111 Name=Test Example
[::ffff:198.51.100.10]:59234 - "(user02)@(CT)" "31/Jul/2025:14:41:23.073 +0530" 1.2 tunnel 203.0.113.20 -1 112639 137450 165 W"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24"
198.51.100.10:59260 - "(user02)@(CT)" "31/Jul/2025:14:40:47.815 +0530" 1.2 flow:tcp 203.0.113.20:443 0 5436 129963 125 W"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24"
[29/Jul/2025:14:02:38.051761 +0000] gateway-kernel-01.example.com 000000 kp 0000020a Internal Misc <KERNEL> created channel (pid=6268):0000000021ce9936
[6/3/2025 00:32:36.115] E-Class SMASSLVPN 002421 ps 100004b3 Info EWACL User ' (198.51.100.10 (user-example)@(group01)' connecting from '198.51.100.10:37975' matched rule 'accessRule(AV1091719670706:preauth access rule)', access to '127.0.0.1:455' is permitted.
[6/3/2025 00:32:36.115 +0000] E-Class SMASSLVPN 027186 uk 00000001 Verbose System ::API::FAKEA145dFYNZimCKNWHB7p2q2Y=::(user01)@(group01)::CLIENT:: Interrogation: Evaluation of OPSWATAV AV1128462569762A [NortonAV.dll,Symantec Corp.,Symantec Client Security,>=,9.x,,,,,FALSE] results: FALSE
[02/Jul/2025:18:47:29.113075 +0000] SMAnode 013581 ps 00000000 Info System Auth: CRL-CERT: Cert verification status = 0, err = 19, reason = 'self-signed certificate in certificate chain', subject='/C=US/ST=Washington/L=Seattle/O=SonicWall/OU=Engineering/CN=Untrusted CA'
https://gateway.internal.example.com:8443/UnregisteredDevices.xml
https://gateway.internal.example.com:8443/UnregisteredDevices.xml?lastLoginTime=2026-08-07T12:00:00Z&platform=Windows&realm=Students&username=user.test&exported=true&deviceCount=10&limit=100
198.51.100.10 - (user01)@(AD) [6/3/2025 00:32:36.115 +0000] "GET /workplace/access/home HTTP/1.1" 200 15424
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:24 +0530 DEBUG - GOT: CredentialsManager[teamSessionId=FAKESESSIONID7QuQWL3BGdokQ==,teamcredentials={username=user01} ,credentials={}]
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESS
2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:03:03,617] pcsession: <authorize:exit> uri=smb://fileshare01.example.com/marketing status=SUCCESS
2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:12:15,043] pcsession: <authorize:exit> uri=http://app.internal.example.com status=FAILURE
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESa

Detection section

The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.

Event Categories

The following table lists the data source offered by this integration.

Data Source Description
Asset management Unregistered Device Log Messages expose exported XML device inventory context.
Authentication logs WorkPlace Logs provide portal shortcut and authorization troubleshooting telemetry.
Host network interface Network Tunnel Audit Log captures tunnel and flow records with endpoint metadata.
Network device configuration Management Audit Log records administrative configuration changes.
Network device logs System Message Log provides core system/service telemetry and policy decision traces.
Services Management Message Log provides AMC operational telemetry.
Web logs Management Access Log captures administrative console HTTP access.
Web proxy Web Proxy Audit Log captures proxy HTTP access records.

In details, the following table denotes the type of events produced by this integration.

Name Values
Kind event
Category authentication, configuration, host, iam, network
Type change, connection, info

Transformed Events Samples after Ingestion

This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.

{
    "message": "127.0.0.1 - admin [25/Jul/2025:05:30:52 -0700] \"GET /Console/PendingChanges HTTP/1.1\" 200 308",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "sonicwall.sma.1000.management_access",
        "kind": "event",
        "outcome": "success",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-07-25T12:30:52Z",
    "http": {
        "request": {
            "method": "GET"
        },
        "response": {
            "bytes": 308,
            "status_code": 200
        },
        "version": "1.1"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "127.0.0.1"
        ],
        "user": [
            "admin"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "console_action": "PendingChanges",
                "http_status_class": "2xx"
            }
        }
    },
    "source": {
        "address": "127.0.0.1",
        "ip": "127.0.0.1"
    },
    "url": {
        "path": "/Console/PendingChanges"
    },
    "user": {
        "name": "admin"
    }
}
{
    "message": "198.51.100.10 - - [01/Jul/2026:15:53:26 +0000] \"POST /j_security_check HTTP/1.1\" 303 0",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "sonicwall.sma.1000.management_access",
        "kind": "event",
        "outcome": "success",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-07-01T15:53:26Z",
    "http": {
        "request": {
            "method": "POST"
        },
        "response": {
            "bytes": 0,
            "status_code": 303
        },
        "version": "1.1"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "198.51.100.10"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "http_status_class": "3xx"
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "ip": "198.51.100.10"
    },
    "url": {
        "path": "/j_security_check"
    }
}
{
    "message": "Info 6/3/2025 00:31:02 admin Applied configuration changes",
    "event": {
        "category": [
            "configuration"
        ],
        "dataset": "sonicwall.sma.1000.management_audit",
        "kind": "event",
        "severity": 6,
        "type": [
            "change"
        ]
    },
    "@timestamp": "2025-06-03T00:31:02Z",
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "user": [
            "admin"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "change_type": "configuration"
            }
        }
    },
    "user": {
        "name": "admin"
    }
}
{
    "message": "2025-07-25T12:31:06+00:00 AMC@gateway01.example.com local4.info AMC: 2025-07-25 12:31:06 +0000 INFO com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2 - Clearing traffic optimizer configuration",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "provider": "AMC:",
        "severity": 6,
        "start": "2025-07-25T12:31:06Z",
        "timezone": "+0000",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-07-25T12:31:06Z",
    "log": {
        "level": "info"
    },
    "observer": {
        "hostname": "gateway01.example.com",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "hosts": [
            "gateway01.example.com"
        ]
    },
    "service": {
        "name": "AMC"
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "management": {
                    "class_name": "com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2"
                },
                "syslog_facility": "local4"
            }
        }
    }
}
{
    "message": "2026-07-01 15:53:26 +0000 INFO    [admin]: Login succeeded - Address=198.51.100.10",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-07-01T15:53:26Z",
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "198.51.100.10"
        ],
        "user": [
            "admin"
        ]
    },
    "source": {
        "address": "198.51.100.10",
        "ip": "198.51.100.10"
    },
    "user": {
        "name": "admin"
    }
}
{
    "message": "pam_unix(cron:session): session closed for user root",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "provider": "cron",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "user": [
            "root"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "unix_auth": {
                    "context_type": "session"
                }
            }
        }
    },
    "user": {
        "name": "root"
    }
}
{
    "message": "2026-07-02 14:33:15 +0000 INFO    [admin]: Adding user group - Name=grp4\n",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-07-02T14:33:15Z",
    "group": {
        "name": "grp4"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "user": [
            "admin"
        ]
    },
    "user": {
        "name": "admin"
    }
}
{
    "message": "2026-07-02 14:48:12 +0000 ERROR     com.aventail.mgmt.jetty.JettyServer - SSL handshake failed: Closed during handshake (198.51.100.10:40236)",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "severity": 3,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-07-02T14:48:12Z",
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "198.51.100.10"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "management": {
                    "class_name": "com.aventail.mgmt.jetty.JettyServer"
                }
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "ip": "198.51.100.10",
        "port": 40236
    }
}
{
    "message": "2026-07-02 14:52:48 +0000 INFO    [admin]: Added address pool - ID=ID1111111111111111 Name=Test Example",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.management_message",
        "kind": "event",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-07-02T14:52:48Z",
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "user": [
            "admin"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "management": {
                    "address_pool": {
                        "id": "ID1111111111111111",
                        "name": "Test Example"
                    }
                }
            }
        }
    },
    "user": {
        "name": "admin"
    }
}
{
    "message": "[::ffff:198.51.100.10]:59234 - \"(user02)@(CT)\" \"31/Jul/2025:14:41:23.073 +0530\" 1.2 tunnel 203.0.113.20 -1 112639 137450 165 W\"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24\"",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "sonicwall.sma.1000.network_tunnel",
        "duration": 165000000000,
        "kind": "event",
        "outcome": "success",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-07-31T09:11:23.073000Z",
    "destination": {
        "address": "203.0.113.20",
        "bytes": 137450,
        "ip": "203.0.113.20"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "W"
    },
    "related": {
        "ip": [
            "198.51.100.10",
            "203.0.113.20"
        ],
        "user": [
            "user02"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "connection_type": "tunnel",
                "equipment_id": "42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24",
                "tunnel_version": "1.2"
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "bytes": 112639,
        "ip": "198.51.100.10",
        "port": 59234,
        "user": {
            "domain": "CT",
            "name": "user02"
        }
    }
}
{
    "message": "198.51.100.10:59260 - \"(user02)@(CT)\" \"31/Jul/2025:14:40:47.815 +0530\" 1.2 flow:tcp 203.0.113.20:443 0 5436 129963 125 W\"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24\"",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "sonicwall.sma.1000.network_tunnel",
        "duration": 125000000000,
        "kind": "event",
        "outcome": "success",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-07-31T09:10:47.815000Z",
    "destination": {
        "address": "203.0.113.20",
        "bytes": 129963,
        "ip": "203.0.113.20",
        "port": 443
    },
    "network": {
        "protocol": "tcp"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "W"
    },
    "related": {
        "ip": [
            "198.51.100.10",
            "203.0.113.20"
        ],
        "user": [
            "user02"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "connection_type": "flow:tcp",
                "equipment_id": "42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24",
                "tunnel_version": "1.2"
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "bytes": 5436,
        "ip": "198.51.100.10",
        "port": 59260,
        "user": {
            "domain": "CT",
            "name": "user02"
        }
    }
}
{
    "message": "[29/Jul/2025:14:02:38.051761 +0000] gateway-kernel-01.example.com 000000 kp 0000020a Internal Misc <KERNEL> created channel (pid=6268):0000000021ce9936",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.system",
        "kind": "event",
        "severity": 0,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-07-29T14:02:38.051761Z",
    "observer": {
        "hostname": "gateway-kernel-01.example.com",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "kp",
        "pid": 6268
    },
    "related": {
        "hosts": [
            "gateway-kernel-01.example.com"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "app_id": "kp",
                "source_id": "0000020a"
            }
        }
    }
}
{
    "message": "[6/3/2025 00:32:36.115] E-Class SMASSLVPN 002421 ps 100004b3 Info EWACL User ' (198.51.100.10 (user-example)@(group01)' connecting from '198.51.100.10:37975' matched rule 'accessRule(AV1091719670706:preauth access rule)', access to '127.0.0.1:455' is permitted.",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.system",
        "kind": "event",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-03T00:32:36.115000Z",
    "destination": {
        "address": "127.0.0.1",
        "ip": "127.0.0.1",
        "port": 455
    },
    "observer": {
        "hostname": "E-Class SMASSLVPN",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "ps",
        "pid": 2421
    },
    "related": {
        "hosts": [
            "E-Class SMASSLVPN"
        ],
        "ip": [
            "127.0.0.1",
            "198.51.100.10"
        ]
    },
    "rule": {
        "id": "AV1091719670706",
        "name": "preauth access rule"
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "app_id": "ps",
                "policy": {
                    "log_type": "EWACL"
                },
                "source_id": "100004b3"
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "ip": "198.51.100.10",
        "port": 37975
    }
}
{
    "message": "[6/3/2025 00:32:36.115 +0000] E-Class SMASSLVPN 027186 uk 00000001 Verbose System ::API::FAKEA145dFYNZimCKNWHB7p2q2Y=::(user01)@(group01)::CLIENT:: Interrogation: Evaluation of OPSWATAV AV1128462569762A [NortonAV.dll,Symantec Corp.,Symantec Client Security,>=,9.x,,,,,FALSE] results: FALSE",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.system",
        "kind": "event",
        "severity": 7,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-03T00:32:36.115000Z",
    "observer": {
        "hostname": "E-Class SMASSLVPN",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "uk",
        "pid": 27186
    },
    "related": {
        "hosts": [
            "E-Class SMASSLVPN"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "app_id": "uk",
                "epc": {
                    "query_result": "FALSE"
                },
                "source_id": "00000001"
            }
        }
    }
}
{
    "message": "[02/Jul/2025:18:47:29.113075 +0000] SMAnode 013581 ps 00000000 Info System Auth: CRL-CERT: Cert verification status = 0, err = 19, reason = 'self-signed certificate in certificate chain', subject='/C=US/ST=Washington/L=Seattle/O=SonicWall/OU=Engineering/CN=Untrusted CA'",
    "event": {
        "category": [
            "host"
        ],
        "dataset": "sonicwall.sma.1000.system",
        "kind": "event",
        "severity": 6,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-07-02T18:47:29.113075Z",
    "observer": {
        "hostname": "SMAnode",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "process": {
        "name": "ps",
        "pid": 13581
    },
    "related": {
        "hosts": [
            "SMAnode"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "app_id": "ps",
                "certificate": {
                    "error_code": 19,
                    "error_reason": "self-signed certificate in certificate chain"
                },
                "source_id": "00000000"
            }
        }
    }
}
{
    "message": "https://gateway.internal.example.com:8443/UnregisteredDevices.xml",
    "event": {
        "category": [
            "iam"
        ],
        "dataset": "sonicwall.sma.1000.unregistered_device",
        "kind": "event",
        "type": [
            "info"
        ]
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    }
}
{
    "message": "https://gateway.internal.example.com:8443/UnregisteredDevices.xml?lastLoginTime=2026-08-07T12:00:00Z&platform=Windows&realm=Students&username=user.test&exported=true&deviceCount=10&limit=100",
    "event": {
        "category": [
            "iam"
        ],
        "dataset": "sonicwall.sma.1000.unregistered_device",
        "kind": "event",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-08-07T12:00:00Z",
    "host": {
        "os": {
            "type": "windows"
        }
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "user": [
            "user.test"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "export_state": "true",
                "registered_device_count": 10,
                "unregistered_device": {
                    "limit": 100
                }
            }
        }
    },
    "user": {
        "domain": "Students",
        "name": "user.test"
    }
}
{
    "message": "198.51.100.10 - (user01)@(AD) [6/3/2025 00:32:36.115 +0000] \"GET /workplace/access/home HTTP/1.1\" 200 15424",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "sonicwall.sma.1000.web_proxy",
        "kind": "event",
        "outcome": "success",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-03T00:32:36.115000Z",
    "http": {
        "request": {
            "method": "GET"
        },
        "response": {
            "bytes": 15424,
            "status_code": 200
        },
        "version": "1.1"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "198.51.100.10"
        ],
        "user": [
            "user01"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "api_endpoint": "/workplace/access/home",
                "http_status_class": "2xx"
            }
        }
    },
    "source": {
        "address": "198.51.100.10",
        "ip": "198.51.100.10",
        "user": {
            "domain": "AD",
            "name": "user01"
        }
    },
    "url": {
        "path": "/workplace/access/home"
    }
}
{
    "message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:24 +0530 DEBUG - GOT: CredentialsManager[teamSessionId=FAKESESSIONID7QuQWL3BGdokQ==,teamcredentials={username=user01} ,credentials={}]",
    "event": {
        "category": [
            "authentication",
            "network"
        ],
        "dataset": "sonicwall.sma.1000.workplace",
        "kind": "event",
        "provider": "WP:",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-30T08:47:23Z",
    "log": {
        "level": "debug"
    },
    "observer": {
        "hostname": "client-gateway.example.com",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "hosts": [
            "client-gateway.example.com"
        ],
        "user": [
            "user01"
        ]
    },
    "service": {
        "name": "WP"
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "workplace": {
                    "team_session_id": "FAKESESSIONID7QuQWL3BGdokQ=="
                }
            }
        }
    },
    "user": {
        "name": "user01"
    }
}
{
    "message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESS",
    "event": {
        "action": "authorize:exit",
        "category": [
            "authentication",
            "network"
        ],
        "dataset": "sonicwall.sma.1000.workplace",
        "kind": "event",
        "outcome": "success",
        "provider": "WP:",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-30T08:47:23Z",
    "log": {
        "level": "debug"
    },
    "observer": {
        "hostname": "client-gateway.example.com",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "hosts": [
            "client-gateway.example.com"
        ]
    },
    "service": {
        "name": "WP"
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "workplace": {
                    "policy_status": "PCL_STATUS_SUCCESS",
                    "shortcut_type": "web"
                }
            }
        }
    },
    "url": {
        "domain": "127.0.0.1",
        "full": "http://127.0.0.1:8085/ctdownload/",
        "original": "http://127.0.0.1:8085/ctdownload/",
        "path": "/ctdownload/",
        "port": 8085,
        "scheme": "http"
    }
}
{
    "message": "2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:03:03,617] pcsession: <authorize:exit> uri=smb://fileshare01.example.com/marketing status=SUCCESS",
    "event": {
        "action": "authorize:exit",
        "category": [
            "authentication",
            "network"
        ],
        "dataset": "sonicwall.sma.1000.workplace",
        "kind": "event",
        "outcome": "success",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-30T08:47:23Z",
    "log": {
        "level": "debug"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "127.0.0.1"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "workplace": {
                    "policy_status": "SUCCESS",
                    "shortcut_type": "network"
                }
            }
        }
    },
    "source": {
        "address": "127.0.0.1",
        "ip": "127.0.0.1"
    },
    "url": {
        "domain": "fileshare01.example.com",
        "original": "smb://fileshare01.example.com/marketing",
        "path": "/marketing",
        "registered_domain": "example.com",
        "scheme": "smb",
        "subdomain": "fileshare01",
        "top_level_domain": "com"
    }
}
{
    "message": "2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:12:15,043] pcsession: <authorize:exit> uri=http://app.internal.example.com status=FAILURE",
    "event": {
        "action": "authorize:exit",
        "category": [
            "authentication",
            "network"
        ],
        "dataset": "sonicwall.sma.1000.workplace",
        "kind": "event",
        "outcome": "failure",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-30T08:47:23Z",
    "log": {
        "level": "debug"
    },
    "observer": {
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "ip": [
            "127.0.0.1"
        ]
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "workplace": {
                    "policy_status": "FAILURE",
                    "shortcut_type": "web"
                }
            }
        }
    },
    "source": {
        "address": "127.0.0.1",
        "ip": "127.0.0.1"
    },
    "url": {
        "domain": "app.internal.example.com",
        "full": "http://app.internal.example.com",
        "original": "http://app.internal.example.com",
        "port": 80,
        "registered_domain": "example.com",
        "scheme": "http",
        "subdomain": "app.internal",
        "top_level_domain": "com"
    }
}
{
    "message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESa",
    "event": {
        "action": "authorize:exit",
        "category": [
            "authentication",
            "network"
        ],
        "dataset": "sonicwall.sma.1000.workplace",
        "kind": "event",
        "provider": "WP:",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-06-30T08:47:23Z",
    "log": {
        "level": "debug"
    },
    "observer": {
        "hostname": "client-gateway.example.com",
        "product": "Secure Mobile Access",
        "type": "firewall",
        "vendor": "SonicWall"
    },
    "related": {
        "hosts": [
            "client-gateway.example.com"
        ]
    },
    "service": {
        "name": "WP"
    },
    "sonicwall": {
        "sma": {
            "1000": {
                "workplace": {
                    "policy_status": "PCL_STATUS_SUCCESa",
                    "shortcut_type": "web"
                }
            }
        }
    },
    "url": {
        "domain": "127.0.0.1",
        "full": "http://127.0.0.1:8085/ctdownload/",
        "original": "http://127.0.0.1:8085/ctdownload/",
        "path": "/ctdownload/",
        "port": 8085,
        "scheme": "http"
    }
}

Extracted Fields

The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.

Name Type Description
@timestamp date Date/time when the event originated.
destination.bytes long Bytes sent from the destination to the source.
destination.ip ip IP address of the destination.
destination.port long Port of the destination.
event.action keyword The action captured by the event.
event.category keyword Event category. The second categorization field in the hierarchy.
event.dataset keyword Name of the dataset.
event.duration long Duration of the event in nanoseconds.
event.kind keyword The kind of the event. The highest categorization field in the hierarchy.
event.outcome keyword The outcome of the event. The lowest level categorization field in the hierarchy.
event.provider keyword Source of the event.
event.severity long Numeric severity of the event.
event.start date event.start contains the date when the event started or when the activity was first observed.
event.timezone keyword Event time zone.
event.type keyword Event type. The third categorization field in the hierarchy.
group.name keyword Name of the group.
host.os.type keyword Which commercial OS family (one of: linux, macos, unix or windows).
http.request.method keyword HTTP request method.
http.response.bytes long Total size in bytes of the response (body and headers).
http.response.status_code long HTTP response status code.
http.version keyword HTTP version.
log.level keyword Log level of the log event.
message match_only_text Log message optimized for viewing in a log viewer.
network.protocol keyword Application protocol name.
observer.hostname keyword Hostname of the observer.
observer.product keyword The product name of the observer.
observer.type keyword The type of the observer the data is coming from.
observer.vendor keyword Vendor name of the observer.
process.name keyword Process name.
process.pid long Process id.
rule.id keyword Rule ID
rule.name keyword Rule name
service.name keyword Name of the service.
sonicwall.sma.1000.api_endpoint keyword Extracted HTTP endpoint path for proxy requests
sonicwall.sma.1000.app_id keyword Application or service identifier found in system message logs
sonicwall.sma.1000.certificate.error_code long Certificate verification error code from client certificate checks
sonicwall.sma.1000.certificate.error_reason keyword Certificate verification error reason from client certificate checks
sonicwall.sma.1000.change_type keyword Derived category of management audit change
sonicwall.sma.1000.connection_type keyword Connection family for network tunnel logs such as tunnel or flow protocol
sonicwall.sma.1000.console_action keyword Derived management console action from requested URL path
sonicwall.sma.1000.epc.query_result keyword Endpoint control interrogation evaluation result
sonicwall.sma.1000.equipment_id keyword Equipment identifier emitted in network tunnel audit logs
sonicwall.sma.1000.export_state keyword Exported or unexported selector from unregistered device URL parameters
sonicwall.sma.1000.http_status_class keyword Derived HTTP response class such as 2xx, 3xx, 4xx, or 5xx
sonicwall.sma.1000.management.address_pool.id keyword Address pool identifier extracted from management plain messages
sonicwall.sma.1000.management.address_pool.name keyword Address pool name extracted from management plain messages
sonicwall.sma.1000.management.class_name keyword Java class name extracted from management service messages
sonicwall.sma.1000.policy.log_type keyword Access policy log family indicator such as CSACL, EWACL, WPACL, or NEACL
sonicwall.sma.1000.registered_device_count long Registered device count filter from unregistered device URL parameters
sonicwall.sma.1000.source_id keyword Internal system source identifier token extracted from system message logs
sonicwall.sma.1000.syslog_facility keyword Syslog facility extracted from management and workplace local facility labels
sonicwall.sma.1000.tunnel_version keyword Tunnel protocol version from network tunnel audit logs
sonicwall.sma.1000.unix_auth.context_type keyword PAM unix authentication context subtype extracted after the provider
sonicwall.sma.1000.unregistered_device.limit long Maximum unregistered device entries requested in export URL
sonicwall.sma.1000.workplace.policy_status keyword Raw policy status value observed in workplace authorization logs
sonicwall.sma.1000.workplace.shortcut_type keyword Derived workplace shortcut type based on URI scheme
sonicwall.sma.1000.workplace.team_session_id keyword Team session identifier extracted from workplace credential manager messages
source.bytes long Bytes sent from the source to the destination.
source.ip ip IP address of the source.
source.port long Port of the source.
source.user.domain keyword Name of the directory the user is a member of.
source.user.name keyword Short name or login of the user.
url.original wildcard Unmodified original url as seen in the event source.
url.path wildcard Path of the request, such as "/search".
user.domain keyword Name of the directory the user is a member of.
user.name keyword Short name or login of the user.

For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.