icon-unified.svg
Experience Center

NSS Feed Output Format: Tunnel Logs

This article includes table pagination. Use the Search function in the tables to find your desired field.

The tunnel Nanolog Streaming Service (NSS) feed specifies the data from the tunnel logs that the NSS sends to the security information and event management (SIEM) system. You can configure an NSS feed by including one or more fields. The fields and their values display in the NSS feed output.

  • "Thu Jun 23 16:24:59 2022","Tunnel Samples","GRE","NA(GRE Tunnel)","new-gre","10.66.89.115","10.66.68.68","0","2","3","160","753","0","7112472280601133057"
        
    Close

The following tables display information about the tunnel log fields and possible values for those fields.

Fields that support obfuscation are documented in the following tables with the prefix o (e.g., %s{olocation}). To obfuscate a field, manually add the prefix o before the field name in the Feed Output Format in the Admin Portal.

IKE Phase 1

IKE Phase 2

Tunnel Events

Tunnel Samples

Related Articles
General Guidelines for NSS Feeds and Feed FormatsNSS Feed Output Format: Web LogsNSS Feed Output Format: Firewall LogsNSS Feed Output Format: DNS LogsNSS Feed Output Format: Tunnel LogsNSS Feed Output Format: SaaS Security LogsNSS Feed Output Format: SaaS Security Activity LogsNSS Feed Output Format: Admin Audit LogsNSS Feed Output Format: Endpoint DLP LogsNSS Feed Output Format: Email DLP Logs