VisiCore AI — Extending X10
X10 Dividend

Log Source Field References

Wire format and vendor field documentation for each benchmarked log source.

Wire format and vendor field documentation for the sources in the benchmark tables. Format selects the reduction method: JSON sources reserialize to CSV at 60–68%, and fixed-order formats trim by dropping named fields.

Links resolve as of 17 July 2026. Cisco and Red Hat block automated link checks — open those by hand. Volume-driver notes need a human check before client-facing use. Sample log lines appear only where a direct fetch confirmed them character for character.

Firewall and session logs

SourceWire formatField referenceVolume driver
Palo Alto — TrafficComma-separated, over syslogTraffic Log FieldsThreat/Content Type start and end — one record each per session
Palo Alto — ThreatComma-separated, over syslogThreat Log FieldsInformational severities
Palo Alto — other typesComma-separated, over syslogSyslog Field DescriptionsSystem, Config, HIP Match, User-ID, GlobalProtect
Cisco ASAsyslog RFC 3164; free text after %ASA-<sev>-<id>ASA Syslog Messages302013–302016 — TCP and UDP build and teardown
Cisco Firepower / FTDsyslogFTD Security Event Syslog Messages430002 connection start, 430003 connection end
FortiGatekey=value default; CSV and CEF selectableLog Message Fieldstype=traffic subtype=forward
Check Pointsyslog, CEF, LEEF, or JSONLog ExporterConnection accept logs
Juniper SRXsyslog RFC 3164 traditional, or RFC 5424 structuredFlow Session MonitoringRT_FLOW_SESSION_CREATE, RT_FLOW_SESSION_CLOSE

Web proxy and DNS

SourceWire formatField referenceVolume driver
Zscaler ZIA — webAdmin-defined feed templateNSS Feed Output Format: Web LogsOne record per web transaction
Zscaler ZIA — firewallAdmin-defined feed templateNSS Feed Output Format: Firewall LogsAllowed-traffic records
Zscaler ZPACSV, JSON, or TSVUser Activity Log FieldsSession and connection records
Infoblox DNSsyslog; BIND named textDNS Response Message Format and ExamplesOne record per resolution

Zscaler NSS feeds carry no fixed field order. An administrator composes the output from a feed template, so the field dictionary rather than a sample line defines the contract.

Cloud platform logs

SourceWire formatField referenceVolume driver
AWS VPC Flow LogsSpace-delimited plain text; Parquet available for S3 deliveryFlow log recordsOne record per flow, per aggregation interval, per interface. A 1-minute interval produces more records than the 10-minute default
AWS CloudTrailJSON, nested, Records arrayRecord contentsRead-only Describe and List calls

Network monitoring and IDS

SourceWire formatField referenceVolume driver
Zeek — conn.logTab-separated default; JSON via LogAscii::use_jsonconn.log fieldsOne record per connection; conn.log is the largest log
Suricata — EVENewline-delimited JSONEVE JSON formatevent_type flow and alert
NetFlow / IPFIXBinary protocol, collector-decodedIPFIX — RFC 7011One record per flow

Endpoint and operating system

SourceWire formatField referenceVolume driver
Windows Security — logonEVTX / XMLEvent 4624Fleet-wide logons; network logons
Windows SysmonEVTX / XML, channel Microsoft/Windows/Sysmon/OperationalSysmonEvent ID 1 process create, 3 network connect, 11 file create
Linux auditdkey=value, several records per eventUnderstanding Audit Log FilesOne command execution emits SYSCALL, EXECVE, CWD, PATH, and PROCTITLE records sharing one event ID

Identity, SaaS, and email

SourceWire formatField referenceVolume driver
Microsoft 365 Unified Audit LogJSON, AuditRecord common schemaManagement Activity API schemaExchange, SharePoint, and Entra workload events
Exchange message trackingCSV, one event per lineMessage trackingRECEIVE, SEND, DELIVER events per message hop

Application delivery

SourceWire formatField referenceVolume driver
F5 BIG-IP ASMCSV, key=value, or CEFLogging Application Security EventsPer-request records; health checks
Cisco MerakisyslogSyslog Event Types and Log Samplesflows and urls roles

Verbatim sample lines live on the samples page. Reduction methods and their measured results live on the levers page.

Gaps

These sources still need a verified field reference. Cisco and Red Hat block automated checks, so their entries above carry a documentation URL that a human opens; the sources below need both the URL and a format confirmed by a direct read.

  • Okta System Log, Azure Activity, Azure NSG flow, and Entra ID sign-in
  • GCP VPC Flow, GCP Cloud Audit, and Google Workspace audit
  • CrowdStrike Falcon Data Replicator, Microsoft Defender for Endpoint, SentinelOne, and Carbon Black
  • Blue Coat ProxySG, Netskope, Cloudflare Logpush, Akamai, and Squid
  • Snort, Cisco IOS and NX-OS device syslog, Cisco ISE, and Cisco Umbrella
  • Kubernetes audit and container logs, web server access logs, DHCP, F5 APM, and NetScaler
  • vSphere metrics — the reference belongs to ESXi and vCenter syslog. Aria Operations for Logs consumes logs rather than emitting them

On this page