Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium

A network security engineer observes a sudden spike in 'spyware' detections in the Threat Logs. To investigate further, they need to identify the specific applications involved in these spyware events. Which field in the Threat Logs provides this application information?

  1. Asubtype
  2. Bapp
  3. Caction
  4. Dproto
Show answer & explanation

Correct answer: B. app

The 'app' (application) field in Palo Alto Networks logs, including Threat Logs, identifies the specific application associated with the traffic that triggered the log entry. This is crucial for understanding which applications are involved in security events.

Why the other options are wrong

  • A. The 'subtype' field provides a more granular classification of the threat (e.g., 'virus', 'spyware'), but not the application itself.
  • C. The 'action' field describes what the firewall did (e.g., alert, block), not the application involved.
  • D. The 'proto' (protocol) field indicates the network protocol (e.g., TCP, UDP), not the application.

Palo Alto Log Fields (App)

The 'app' field in Palo Alto Networks logs identifies the specific application (e.g., 'facebook-base', 'ms-rdp') that the firewall detected for a given session or security event, leveraging App-ID technology.

  • Crucial for application-based policy enforcement and monitoring.
  • Found across various log types (Traffic, Threat, URL Filtering).
  • Provides visibility beyond simple port/protocol identification.

Memory trick: Each field is a label, telling a part of the log's story.

More Monitoring and Reporting questions