SonicWall SMA 1000 Series
Overview
SonicWall Secure Mobile Access 1000 Series logs are structured text-based records (mostly syslog-like and HTTP access formats, with XML exports) that capture timestamped system, administrative, access, tunnel, flow, web proxy, unregistered device, and WorkPlace events for monitoring, auditing, and incident analysis.
- Vendor: SonicWall
- Supported environment: On prem
- Version compatibility: 12.5
- Detection based on: Telemetry
- Supported application or feature: DNS records
Configure
This setup guide will show you how to forward your SonicWall SMA 1000 Series logs to Sekoia.io by means of a syslog transport channel.
Prerequisites
- Have an internal log concentrator (Rsyslog).
Enable Syslog forwarding for SonicWall SMA 1000 Series
- Log in the SonicWall SMA Appliance Management Console.
- Go to
Monitoring > Logging > Configure Logging. - In the
Services Log Levelsection, define the severity level of log messages. -
In the
Syslog Configurationsection, type the IP address and the port of your log concentrator as primary syslog server (Server #1).
-
Click
Saveto save your logging settings.
Create the intake
Go to the intake page and create a new intake from the SonicWall SMA 1000 Series format.
Forward logs to Sekoia.io
Please consult the Syslog Forwarding documentation to forward these logs to Sekoia.io.
Raw Events Samples
In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.
127.0.0.1 - admin [25/Jul/2025:05:30:52 -0700] "GET /Console/PendingChanges HTTP/1.1" 200 308
198.51.100.10 - - [01/Jul/2026:15:53:26 +0000] "POST /j_security_check HTTP/1.1" 303 0
Info 6/3/2025 00:31:02 admin Applied configuration changes
2025-07-25T12:31:06+00:00 AMC@gateway01.example.com local4.info AMC: 2025-07-25 12:31:06 +0000 INFO com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2 - Clearing traffic optimizer configuration
2026-07-01 15:53:26 +0000 INFO [admin]: Login succeeded - Address=198.51.100.10
pam_unix(cron:session): session closed for user root
2026-07-02 14:33:15 +0000 INFO [admin]: Adding user group - Name=grp4
2026-07-02 14:48:12 +0000 ERROR com.aventail.mgmt.jetty.JettyServer - SSL handshake failed: Closed during handshake (198.51.100.10:40236)
2026-07-02 14:52:48 +0000 INFO [admin]: Added address pool - ID=ID1111111111111111 Name=Test Example
[::ffff:198.51.100.10]:59234 - "(user02)@(CT)" "31/Jul/2025:14:41:23.073 +0530" 1.2 tunnel 203.0.113.20 -1 112639 137450 165 W"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24"
198.51.100.10:59260 - "(user02)@(CT)" "31/Jul/2025:14:40:47.815 +0530" 1.2 flow:tcp 203.0.113.20:443 0 5436 129963 125 W"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24"
[29/Jul/2025:14:02:38.051761 +0000] gateway-kernel-01.example.com 000000 kp 0000020a Internal Misc <KERNEL> created channel (pid=6268):0000000021ce9936
[6/3/2025 00:32:36.115] E-Class SMASSLVPN 002421 ps 100004b3 Info EWACL User ' (198.51.100.10 (user-example)@(group01)' connecting from '198.51.100.10:37975' matched rule 'accessRule(AV1091719670706:preauth access rule)', access to '127.0.0.1:455' is permitted.
[6/3/2025 00:32:36.115 +0000] E-Class SMASSLVPN 027186 uk 00000001 Verbose System ::API::FAKEA145dFYNZimCKNWHB7p2q2Y=::(user01)@(group01)::CLIENT:: Interrogation: Evaluation of OPSWATAV AV1128462569762A [NortonAV.dll,Symantec Corp.,Symantec Client Security,>=,9.x,,,,,FALSE] results: FALSE
[02/Jul/2025:18:47:29.113075 +0000] SMAnode 013581 ps 00000000 Info System Auth: CRL-CERT: Cert verification status = 0, err = 19, reason = 'self-signed certificate in certificate chain', subject='/C=US/ST=Washington/L=Seattle/O=SonicWall/OU=Engineering/CN=Untrusted CA'
https://gateway.internal.example.com:8443/UnregisteredDevices.xml
https://gateway.internal.example.com:8443/UnregisteredDevices.xml?lastLoginTime=2026-08-07T12:00:00Z&platform=Windows&realm=Students&username=user.test&exported=true&deviceCount=10&limit=100
198.51.100.10 - (user01)@(AD) [6/3/2025 00:32:36.115 +0000] "GET /workplace/access/home HTTP/1.1" 200 15424
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:24 +0530 DEBUG - GOT: CredentialsManager[teamSessionId=FAKESESSIONID7QuQWL3BGdokQ==,teamcredentials={username=user01} ,credentials={}]
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESS
2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:03:03,617] pcsession: <authorize:exit> uri=smb://fileshare01.example.com/marketing status=SUCCESS
2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:12:15,043] pcsession: <authorize:exit> uri=http://app.internal.example.com status=FAILURE
2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESa
Detection section
The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.
Event Categories
The following table lists the data source offered by this integration.
| Data Source | Description |
|---|---|
Asset management |
Unregistered Device Log Messages expose exported XML device inventory context. |
Authentication logs |
WorkPlace Logs provide portal shortcut and authorization troubleshooting telemetry. |
Host network interface |
Network Tunnel Audit Log captures tunnel and flow records with endpoint metadata. |
Network device configuration |
Management Audit Log records administrative configuration changes. |
Network device logs |
System Message Log provides core system/service telemetry and policy decision traces. |
Services |
Management Message Log provides AMC operational telemetry. |
Web logs |
Management Access Log captures administrative console HTTP access. |
Web proxy |
Web Proxy Audit Log captures proxy HTTP access records. |
In details, the following table denotes the type of events produced by this integration.
| Name | Values |
|---|---|
| Kind | event |
| Category | authentication, configuration, host, iam, network |
| Type | change, connection, info |
Transformed Events Samples after Ingestion
This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.
{
"message": "127.0.0.1 - admin [25/Jul/2025:05:30:52 -0700] \"GET /Console/PendingChanges HTTP/1.1\" 200 308",
"event": {
"category": [
"network"
],
"dataset": "sonicwall.sma.1000.management_access",
"kind": "event",
"outcome": "success",
"type": [
"info"
]
},
"@timestamp": "2025-07-25T12:30:52Z",
"http": {
"request": {
"method": "GET"
},
"response": {
"bytes": 308,
"status_code": 200
},
"version": "1.1"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"127.0.0.1"
],
"user": [
"admin"
]
},
"sonicwall": {
"sma": {
"1000": {
"console_action": "PendingChanges",
"http_status_class": "2xx"
}
}
},
"source": {
"address": "127.0.0.1",
"ip": "127.0.0.1"
},
"url": {
"path": "/Console/PendingChanges"
},
"user": {
"name": "admin"
}
}
{
"message": "198.51.100.10 - - [01/Jul/2026:15:53:26 +0000] \"POST /j_security_check HTTP/1.1\" 303 0",
"event": {
"category": [
"network"
],
"dataset": "sonicwall.sma.1000.management_access",
"kind": "event",
"outcome": "success",
"type": [
"info"
]
},
"@timestamp": "2026-07-01T15:53:26Z",
"http": {
"request": {
"method": "POST"
},
"response": {
"bytes": 0,
"status_code": 303
},
"version": "1.1"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"198.51.100.10"
]
},
"sonicwall": {
"sma": {
"1000": {
"http_status_class": "3xx"
}
}
},
"source": {
"address": "198.51.100.10",
"ip": "198.51.100.10"
},
"url": {
"path": "/j_security_check"
}
}
{
"message": "Info 6/3/2025 00:31:02 admin Applied configuration changes",
"event": {
"category": [
"configuration"
],
"dataset": "sonicwall.sma.1000.management_audit",
"kind": "event",
"severity": 6,
"type": [
"change"
]
},
"@timestamp": "2025-06-03T00:31:02Z",
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"user": [
"admin"
]
},
"sonicwall": {
"sma": {
"1000": {
"change_type": "configuration"
}
}
},
"user": {
"name": "admin"
}
}
{
"message": "2025-07-25T12:31:06+00:00 AMC@gateway01.example.com local4.info AMC: 2025-07-25 12:31:06 +0000 INFO com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2 - Clearing traffic optimizer configuration",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"provider": "AMC:",
"severity": 6,
"start": "2025-07-25T12:31:06Z",
"timezone": "+0000",
"type": [
"info"
]
},
"@timestamp": "2025-07-25T12:31:06Z",
"log": {
"level": "info"
},
"observer": {
"hostname": "gateway01.example.com",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"hosts": [
"gateway01.example.com"
]
},
"service": {
"name": "AMC"
},
"sonicwall": {
"sma": {
"1000": {
"management": {
"class_name": "com.aventail.mgmt.rest.console.centralmanagement.managed.sharedstate.TrafficOptimizerConfigurationResource12_2"
},
"syslog_facility": "local4"
}
}
}
}
{
"message": "2026-07-01 15:53:26 +0000 INFO [admin]: Login succeeded - Address=198.51.100.10",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"severity": 6,
"type": [
"info"
]
},
"@timestamp": "2026-07-01T15:53:26Z",
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"198.51.100.10"
],
"user": [
"admin"
]
},
"source": {
"address": "198.51.100.10",
"ip": "198.51.100.10"
},
"user": {
"name": "admin"
}
}
{
"message": "pam_unix(cron:session): session closed for user root",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"provider": "cron",
"severity": 6,
"type": [
"info"
]
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"user": [
"root"
]
},
"sonicwall": {
"sma": {
"1000": {
"unix_auth": {
"context_type": "session"
}
}
}
},
"user": {
"name": "root"
}
}
{
"message": "2026-07-02 14:33:15 +0000 INFO [admin]: Adding user group - Name=grp4\n",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"severity": 6,
"type": [
"info"
]
},
"@timestamp": "2026-07-02T14:33:15Z",
"group": {
"name": "grp4"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"user": [
"admin"
]
},
"user": {
"name": "admin"
}
}
{
"message": "2026-07-02 14:48:12 +0000 ERROR com.aventail.mgmt.jetty.JettyServer - SSL handshake failed: Closed during handshake (198.51.100.10:40236)",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"severity": 3,
"type": [
"info"
]
},
"@timestamp": "2026-07-02T14:48:12Z",
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"198.51.100.10"
]
},
"sonicwall": {
"sma": {
"1000": {
"management": {
"class_name": "com.aventail.mgmt.jetty.JettyServer"
}
}
}
},
"source": {
"address": "198.51.100.10",
"ip": "198.51.100.10",
"port": 40236
}
}
{
"message": "2026-07-02 14:52:48 +0000 INFO [admin]: Added address pool - ID=ID1111111111111111 Name=Test Example",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.management_message",
"kind": "event",
"severity": 6,
"type": [
"info"
]
},
"@timestamp": "2026-07-02T14:52:48Z",
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"user": [
"admin"
]
},
"sonicwall": {
"sma": {
"1000": {
"management": {
"address_pool": {
"id": "ID1111111111111111",
"name": "Test Example"
}
}
}
}
},
"user": {
"name": "admin"
}
}
{
"message": "[::ffff:198.51.100.10]:59234 - \"(user02)@(CT)\" \"31/Jul/2025:14:41:23.073 +0530\" 1.2 tunnel 203.0.113.20 -1 112639 137450 165 W\"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24\"",
"event": {
"category": [
"network"
],
"dataset": "sonicwall.sma.1000.network_tunnel",
"duration": 165000000000,
"kind": "event",
"outcome": "success",
"type": [
"connection"
]
},
"@timestamp": "2025-07-31T09:11:23.073000Z",
"destination": {
"address": "203.0.113.20",
"bytes": 137450,
"ip": "203.0.113.20"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "W"
},
"related": {
"ip": [
"198.51.100.10",
"203.0.113.20"
],
"user": [
"user02"
]
},
"sonicwall": {
"sma": {
"1000": {
"connection_type": "tunnel",
"equipment_id": "42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24",
"tunnel_version": "1.2"
}
}
},
"source": {
"address": "198.51.100.10",
"bytes": 112639,
"ip": "198.51.100.10",
"port": 59234,
"user": {
"domain": "CT",
"name": "user02"
}
}
}
{
"message": "198.51.100.10:59260 - \"(user02)@(CT)\" \"31/Jul/2025:14:40:47.815 +0530\" 1.2 flow:tcp 203.0.113.20:443 0 5436 129963 125 W\"42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24\"",
"event": {
"category": [
"network"
],
"dataset": "sonicwall.sma.1000.network_tunnel",
"duration": 125000000000,
"kind": "event",
"outcome": "success",
"type": [
"connection"
]
},
"@timestamp": "2025-07-31T09:10:47.815000Z",
"destination": {
"address": "203.0.113.20",
"bytes": 129963,
"ip": "203.0.113.20",
"port": 443
},
"network": {
"protocol": "tcp"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "W"
},
"related": {
"ip": [
"198.51.100.10",
"203.0.113.20"
],
"user": [
"user02"
]
},
"sonicwall": {
"sma": {
"1000": {
"connection_type": "flow:tcp",
"equipment_id": "42 1a 69 3a 6c 75 ac eb-be 8a 0b 90 9b 13 c6 24",
"tunnel_version": "1.2"
}
}
},
"source": {
"address": "198.51.100.10",
"bytes": 5436,
"ip": "198.51.100.10",
"port": 59260,
"user": {
"domain": "CT",
"name": "user02"
}
}
}
{
"message": "[29/Jul/2025:14:02:38.051761 +0000] gateway-kernel-01.example.com 000000 kp 0000020a Internal Misc <KERNEL> created channel (pid=6268):0000000021ce9936",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.system",
"kind": "event",
"severity": 0,
"type": [
"info"
]
},
"@timestamp": "2025-07-29T14:02:38.051761Z",
"observer": {
"hostname": "gateway-kernel-01.example.com",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "kp",
"pid": 6268
},
"related": {
"hosts": [
"gateway-kernel-01.example.com"
]
},
"sonicwall": {
"sma": {
"1000": {
"app_id": "kp",
"source_id": "0000020a"
}
}
}
}
{
"message": "[6/3/2025 00:32:36.115] E-Class SMASSLVPN 002421 ps 100004b3 Info EWACL User ' (198.51.100.10 (user-example)@(group01)' connecting from '198.51.100.10:37975' matched rule 'accessRule(AV1091719670706:preauth access rule)', access to '127.0.0.1:455' is permitted.",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.system",
"kind": "event",
"severity": 6,
"type": [
"info"
]
},
"@timestamp": "2025-06-03T00:32:36.115000Z",
"destination": {
"address": "127.0.0.1",
"ip": "127.0.0.1",
"port": 455
},
"observer": {
"hostname": "E-Class SMASSLVPN",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "ps",
"pid": 2421
},
"related": {
"hosts": [
"E-Class SMASSLVPN"
],
"ip": [
"127.0.0.1",
"198.51.100.10"
]
},
"rule": {
"id": "AV1091719670706",
"name": "preauth access rule"
},
"sonicwall": {
"sma": {
"1000": {
"app_id": "ps",
"policy": {
"log_type": "EWACL"
},
"source_id": "100004b3"
}
}
},
"source": {
"address": "198.51.100.10",
"ip": "198.51.100.10",
"port": 37975
}
}
{
"message": "[6/3/2025 00:32:36.115 +0000] E-Class SMASSLVPN 027186 uk 00000001 Verbose System ::API::FAKEA145dFYNZimCKNWHB7p2q2Y=::(user01)@(group01)::CLIENT:: Interrogation: Evaluation of OPSWATAV AV1128462569762A [NortonAV.dll,Symantec Corp.,Symantec Client Security,>=,9.x,,,,,FALSE] results: FALSE",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.system",
"kind": "event",
"severity": 7,
"type": [
"info"
]
},
"@timestamp": "2025-06-03T00:32:36.115000Z",
"observer": {
"hostname": "E-Class SMASSLVPN",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "uk",
"pid": 27186
},
"related": {
"hosts": [
"E-Class SMASSLVPN"
]
},
"sonicwall": {
"sma": {
"1000": {
"app_id": "uk",
"epc": {
"query_result": "FALSE"
},
"source_id": "00000001"
}
}
}
}
{
"message": "[02/Jul/2025:18:47:29.113075 +0000] SMAnode 013581 ps 00000000 Info System Auth: CRL-CERT: Cert verification status = 0, err = 19, reason = 'self-signed certificate in certificate chain', subject='/C=US/ST=Washington/L=Seattle/O=SonicWall/OU=Engineering/CN=Untrusted CA'",
"event": {
"category": [
"host"
],
"dataset": "sonicwall.sma.1000.system",
"kind": "event",
"severity": 6,
"type": [
"info"
]
},
"@timestamp": "2025-07-02T18:47:29.113075Z",
"observer": {
"hostname": "SMAnode",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"process": {
"name": "ps",
"pid": 13581
},
"related": {
"hosts": [
"SMAnode"
]
},
"sonicwall": {
"sma": {
"1000": {
"app_id": "ps",
"certificate": {
"error_code": 19,
"error_reason": "self-signed certificate in certificate chain"
},
"source_id": "00000000"
}
}
}
}
{
"message": "https://gateway.internal.example.com:8443/UnregisteredDevices.xml",
"event": {
"category": [
"iam"
],
"dataset": "sonicwall.sma.1000.unregistered_device",
"kind": "event",
"type": [
"info"
]
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
}
}
{
"message": "https://gateway.internal.example.com:8443/UnregisteredDevices.xml?lastLoginTime=2026-08-07T12:00:00Z&platform=Windows&realm=Students&username=user.test&exported=true&deviceCount=10&limit=100",
"event": {
"category": [
"iam"
],
"dataset": "sonicwall.sma.1000.unregistered_device",
"kind": "event",
"type": [
"info"
]
},
"@timestamp": "2026-08-07T12:00:00Z",
"host": {
"os": {
"type": "windows"
}
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"user": [
"user.test"
]
},
"sonicwall": {
"sma": {
"1000": {
"export_state": "true",
"registered_device_count": 10,
"unregistered_device": {
"limit": 100
}
}
}
},
"user": {
"domain": "Students",
"name": "user.test"
}
}
{
"message": "198.51.100.10 - (user01)@(AD) [6/3/2025 00:32:36.115 +0000] \"GET /workplace/access/home HTTP/1.1\" 200 15424",
"event": {
"category": [
"network"
],
"dataset": "sonicwall.sma.1000.web_proxy",
"kind": "event",
"outcome": "success",
"type": [
"info"
]
},
"@timestamp": "2025-06-03T00:32:36.115000Z",
"http": {
"request": {
"method": "GET"
},
"response": {
"bytes": 15424,
"status_code": 200
},
"version": "1.1"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"198.51.100.10"
],
"user": [
"user01"
]
},
"sonicwall": {
"sma": {
"1000": {
"api_endpoint": "/workplace/access/home",
"http_status_class": "2xx"
}
}
},
"source": {
"address": "198.51.100.10",
"ip": "198.51.100.10",
"user": {
"domain": "AD",
"name": "user01"
}
},
"url": {
"path": "/workplace/access/home"
}
}
{
"message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:24 +0530 DEBUG - GOT: CredentialsManager[teamSessionId=FAKESESSIONID7QuQWL3BGdokQ==,teamcredentials={username=user01} ,credentials={}]",
"event": {
"category": [
"authentication",
"network"
],
"dataset": "sonicwall.sma.1000.workplace",
"kind": "event",
"provider": "WP:",
"type": [
"info"
]
},
"@timestamp": "2025-06-30T08:47:23Z",
"log": {
"level": "debug"
},
"observer": {
"hostname": "client-gateway.example.com",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"hosts": [
"client-gateway.example.com"
],
"user": [
"user01"
]
},
"service": {
"name": "WP"
},
"sonicwall": {
"sma": {
"1000": {
"workplace": {
"team_session_id": "FAKESESSIONID7QuQWL3BGdokQ=="
}
}
}
},
"user": {
"name": "user01"
}
}
{
"message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESS",
"event": {
"action": "authorize:exit",
"category": [
"authentication",
"network"
],
"dataset": "sonicwall.sma.1000.workplace",
"kind": "event",
"outcome": "success",
"provider": "WP:",
"type": [
"info"
]
},
"@timestamp": "2025-06-30T08:47:23Z",
"log": {
"level": "debug"
},
"observer": {
"hostname": "client-gateway.example.com",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"hosts": [
"client-gateway.example.com"
]
},
"service": {
"name": "WP"
},
"sonicwall": {
"sma": {
"1000": {
"workplace": {
"policy_status": "PCL_STATUS_SUCCESS",
"shortcut_type": "web"
}
}
}
},
"url": {
"domain": "127.0.0.1",
"full": "http://127.0.0.1:8085/ctdownload/",
"original": "http://127.0.0.1:8085/ctdownload/",
"path": "/ctdownload/",
"port": 8085,
"scheme": "http"
}
}
{
"message": "2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:03:03,617] pcsession: <authorize:exit> uri=smb://fileshare01.example.com/marketing status=SUCCESS",
"event": {
"action": "authorize:exit",
"category": [
"authentication",
"network"
],
"dataset": "sonicwall.sma.1000.workplace",
"kind": "event",
"outcome": "success",
"type": [
"info"
]
},
"@timestamp": "2025-06-30T08:47:23Z",
"log": {
"level": "debug"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"127.0.0.1"
]
},
"sonicwall": {
"sma": {
"1000": {
"workplace": {
"policy_status": "SUCCESS",
"shortcut_type": "network"
}
}
}
},
"source": {
"address": "127.0.0.1",
"ip": "127.0.0.1"
},
"url": {
"domain": "fileshare01.example.com",
"original": "smb://fileshare01.example.com/marketing",
"path": "/marketing",
"registered_domain": "example.com",
"scheme": "smb",
"subdomain": "fileshare01",
"top_level_domain": "com"
}
}
{
"message": "2025-06-30T14:17:23+05:30 127.0.0.1/127.0.0.1 local7.debug DEBUG [22:12:15,043] pcsession: <authorize:exit> uri=http://app.internal.example.com status=FAILURE",
"event": {
"action": "authorize:exit",
"category": [
"authentication",
"network"
],
"dataset": "sonicwall.sma.1000.workplace",
"kind": "event",
"outcome": "failure",
"type": [
"info"
]
},
"@timestamp": "2025-06-30T08:47:23Z",
"log": {
"level": "debug"
},
"observer": {
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"ip": [
"127.0.0.1"
]
},
"sonicwall": {
"sma": {
"1000": {
"workplace": {
"policy_status": "FAILURE",
"shortcut_type": "web"
}
}
}
},
"source": {
"address": "127.0.0.1",
"ip": "127.0.0.1"
},
"url": {
"domain": "app.internal.example.com",
"full": "http://app.internal.example.com",
"original": "http://app.internal.example.com",
"port": 80,
"registered_domain": "example.com",
"scheme": "http",
"subdomain": "app.internal",
"top_level_domain": "com"
}
}
{
"message": "2025-06-30T14:17:23+05:30 WP@client-gateway.example.com local7.debug WP: 2025-06-30 14:17:23 +0530 DEBUG - PolicyClientSession: <authorize:exit> uri=http://127.0.0.1:8085/ctdownload/ status=PCL_STATUS_SUCCESa",
"event": {
"action": "authorize:exit",
"category": [
"authentication",
"network"
],
"dataset": "sonicwall.sma.1000.workplace",
"kind": "event",
"provider": "WP:",
"type": [
"info"
]
},
"@timestamp": "2025-06-30T08:47:23Z",
"log": {
"level": "debug"
},
"observer": {
"hostname": "client-gateway.example.com",
"product": "Secure Mobile Access",
"type": "firewall",
"vendor": "SonicWall"
},
"related": {
"hosts": [
"client-gateway.example.com"
]
},
"service": {
"name": "WP"
},
"sonicwall": {
"sma": {
"1000": {
"workplace": {
"policy_status": "PCL_STATUS_SUCCESa",
"shortcut_type": "web"
}
}
}
},
"url": {
"domain": "127.0.0.1",
"full": "http://127.0.0.1:8085/ctdownload/",
"original": "http://127.0.0.1:8085/ctdownload/",
"path": "/ctdownload/",
"port": 8085,
"scheme": "http"
}
}
Extracted Fields
The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.
| Name | Type | Description |
|---|---|---|
@timestamp |
date |
Date/time when the event originated. |
destination.bytes |
long |
Bytes sent from the destination to the source. |
destination.ip |
ip |
IP address of the destination. |
destination.port |
long |
Port of the destination. |
event.action |
keyword |
The action captured by the event. |
event.category |
keyword |
Event category. The second categorization field in the hierarchy. |
event.dataset |
keyword |
Name of the dataset. |
event.duration |
long |
Duration of the event in nanoseconds. |
event.kind |
keyword |
The kind of the event. The highest categorization field in the hierarchy. |
event.outcome |
keyword |
The outcome of the event. The lowest level categorization field in the hierarchy. |
event.provider |
keyword |
Source of the event. |
event.severity |
long |
Numeric severity of the event. |
event.start |
date |
event.start contains the date when the event started or when the activity was first observed. |
event.timezone |
keyword |
Event time zone. |
event.type |
keyword |
Event type. The third categorization field in the hierarchy. |
group.name |
keyword |
Name of the group. |
host.os.type |
keyword |
Which commercial OS family (one of: linux, macos, unix or windows). |
http.request.method |
keyword |
HTTP request method. |
http.response.bytes |
long |
Total size in bytes of the response (body and headers). |
http.response.status_code |
long |
HTTP response status code. |
http.version |
keyword |
HTTP version. |
log.level |
keyword |
Log level of the log event. |
message |
match_only_text |
Log message optimized for viewing in a log viewer. |
network.protocol |
keyword |
Application protocol name. |
observer.hostname |
keyword |
Hostname of the observer. |
observer.product |
keyword |
The product name of the observer. |
observer.type |
keyword |
The type of the observer the data is coming from. |
observer.vendor |
keyword |
Vendor name of the observer. |
process.name |
keyword |
Process name. |
process.pid |
long |
Process id. |
rule.id |
keyword |
Rule ID |
rule.name |
keyword |
Rule name |
service.name |
keyword |
Name of the service. |
sonicwall.sma.1000.api_endpoint |
keyword |
Extracted HTTP endpoint path for proxy requests |
sonicwall.sma.1000.app_id |
keyword |
Application or service identifier found in system message logs |
sonicwall.sma.1000.certificate.error_code |
long |
Certificate verification error code from client certificate checks |
sonicwall.sma.1000.certificate.error_reason |
keyword |
Certificate verification error reason from client certificate checks |
sonicwall.sma.1000.change_type |
keyword |
Derived category of management audit change |
sonicwall.sma.1000.connection_type |
keyword |
Connection family for network tunnel logs such as tunnel or flow protocol |
sonicwall.sma.1000.console_action |
keyword |
Derived management console action from requested URL path |
sonicwall.sma.1000.epc.query_result |
keyword |
Endpoint control interrogation evaluation result |
sonicwall.sma.1000.equipment_id |
keyword |
Equipment identifier emitted in network tunnel audit logs |
sonicwall.sma.1000.export_state |
keyword |
Exported or unexported selector from unregistered device URL parameters |
sonicwall.sma.1000.http_status_class |
keyword |
Derived HTTP response class such as 2xx, 3xx, 4xx, or 5xx |
sonicwall.sma.1000.management.address_pool.id |
keyword |
Address pool identifier extracted from management plain messages |
sonicwall.sma.1000.management.address_pool.name |
keyword |
Address pool name extracted from management plain messages |
sonicwall.sma.1000.management.class_name |
keyword |
Java class name extracted from management service messages |
sonicwall.sma.1000.policy.log_type |
keyword |
Access policy log family indicator such as CSACL, EWACL, WPACL, or NEACL |
sonicwall.sma.1000.registered_device_count |
long |
Registered device count filter from unregistered device URL parameters |
sonicwall.sma.1000.source_id |
keyword |
Internal system source identifier token extracted from system message logs |
sonicwall.sma.1000.syslog_facility |
keyword |
Syslog facility extracted from management and workplace local facility labels |
sonicwall.sma.1000.tunnel_version |
keyword |
Tunnel protocol version from network tunnel audit logs |
sonicwall.sma.1000.unix_auth.context_type |
keyword |
PAM unix authentication context subtype extracted after the provider |
sonicwall.sma.1000.unregistered_device.limit |
long |
Maximum unregistered device entries requested in export URL |
sonicwall.sma.1000.workplace.policy_status |
keyword |
Raw policy status value observed in workplace authorization logs |
sonicwall.sma.1000.workplace.shortcut_type |
keyword |
Derived workplace shortcut type based on URI scheme |
sonicwall.sma.1000.workplace.team_session_id |
keyword |
Team session identifier extracted from workplace credential manager messages |
source.bytes |
long |
Bytes sent from the source to the destination. |
source.ip |
ip |
IP address of the source. |
source.port |
long |
Port of the source. |
source.user.domain |
keyword |
Name of the directory the user is a member of. |
source.user.name |
keyword |
Short name or login of the user. |
url.original |
wildcard |
Unmodified original url as seen in the event source. |
url.path |
wildcard |
Path of the request, such as "/search". |
user.domain |
keyword |
Name of the directory the user is a member of. |
user.name |
keyword |
Short name or login of the user. |
For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.