Here is a sample log.
{
“event_source_product”: “PAN”,
“gl2_accounted_message_size”: 1936,
“gl2_receive_timestamp”: “2025-06-24 11:35:55.140”,
“vendor_subtype”: “THREAT”,
“gl2_remote_ip”: “192.168.6.41”,
“gl2_remote_port”: 49847,
“streams”: [
“6852ece450a4235323b5c02f”
],
“gl2_message_id”: “01JYGVJ9BR00F92CBZ9TDFCYS3”,
“source”: “Firewall.company.local”,
“message”: “1,2025/06/24 07:35:54,023201002425,THREAT,url,2818,2025/06/24 07:35:54,10.1.95.109,17.248.210.7,173.241.232.195,17.248.210.7,Remote Locations to Internet,ssl,vsys1,06 LAN,WAN_Zone,ethernet1/2.101,ethernet1/1,Syslog Forward,2025/06/24 07:35:55,20924,1,56966,443,9438,443,0x40b400,tcp,alert,"gateway-asset.icloud-content.com/",(9999),computer-and-internet-info,informational,client-to-server,7517298228159870177,0x0,10.0.0.0-10.255.255.255,United States,0,0,0,0,0,0,0,CDC-FW-01,0,0,N/A,N/A,AppThreat-0-0,0x0,0,4294967295,"computer-and-internet-info,low-risk",c0986931-2ba1-468b-97ae-3b71d4c5b3c9,0,0,2025-06-24T07:35:55.149-04:00,encrypted-tunnel,networking,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",ssl,no,no,NonProxyTraffic,false,0,0,0,0”,
“gl2_source_input”: “6852eb0350a4235323b5b7f3”,
“gl2_processing_timestamp”: “2025-06-24 11:35:55.143”,
“full_message”: “<14>Jun 24 07:35:55 Firewall.company.local 1,2025/06/24 07:35:54,023201002425,THREAT,url,2818,2025/06/24 07:35:54,10.1.95.109,17.248.210.7,173.241.232.195,17.248.210.7,Remote Locations to Internet,ssl,vsys1,06 LAN,WAN_Zone,ethernet1/2.161,ethernet1/1,Syslog Forward,2025/06/24 07:35:55,20924,1,56966,443,9438,443,0x40b400,tcp,alert,"gateway-asset.icloud-content.com/",(9999),computer-and-internet-info,informational,client-to-server,7517298228159870177,0x0,10.0.0.0-10.255.255.255,United States,0,0,0,0,0,0,0,Firewall,0,0,N/A,N/A,AppThreat-0-0,0x0,0,4294967295,"computer-and-internet-info,low-risk",c0986931-2ba1-468b-97ae-3b71d4c5b3c9,0,0,2025-06-24T07:35:55.149-04:00,encrypted-tunnel,networking,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",ssl,no,no,NonProxyTraffic,false,0,0,0,0”,
“gl2_source_node”: “51bb5ab7-7b3a-4b63-8387-e2b9e2a94ca1”,
“_id”: “63deb170-50ef-11f0-8898-0050569e1f4e”,
“gl2_processing_duration_ms”: 3,
“timestamp”: “2025-06-24T11:35:55.000Z”
}