---
title: "Flow log attributes for SIEM integration"
canonical: "https://docs.aryaka.com/space/KNOW/736362516/Flow%20log%20attributes%20for%20SIEM%20integration"
format: markdown
---
Flow logs streamed to a SIEM integration endpoint use an Aryaka proprietary data structure and are formatted in JSON. When you configure SIEM, you can enable these and other supported log types. The following flow log structure is streamed to SIEM: {
  "timestamp": "integer (epoch time in milliseconds)",
  "flow_id": "integer",
  "flow_dir": "string",
  "setup_time": "integer (epoch time in milliseconds)",
  "close_time": "integer (epoch time in milliseconds)",
  "src_ipv4": "string (IPv4 address)",
  "dst_ipv4": "string (IPv4 address)",
  "src_port": "integer",
  "dst_port": "integer",
  "protocol": "integer",
  "src_zone": "string",
  "dst_zone": "string",
  "src_network": "integer",
  "dst_network": "integer",
  "isp2_wan_in": "integer",
  "isp2_wan_out": "integer",
  "site_id": "integer",
  "domain_name": "string (FQDN)"
} The following is an example flow log: {
        "dst_port": 443,
        "src_zone": "vpn0",
        "dst_zone": "public",
        "src_network": "LOCAL",
        "dst_network": "PUBLIC",
        "isp1_wan_in": "156837",
        "isp1_wan_out": "6761",
        "domain_name": "www.wwe.com",
        "site_id": 146635,
        "protocol": 6,
        "flow_id": 224714927,
        "close_time": "1749738980415",
        "flow_dir": "OUTGOING",
        "setup_time": "1749738919728",
        "timestamp": "1749738980415",
        "src_ipv4": "10.12.15.2",
        "dst_ipv4": "151.101.66.133",
        "src_port": 57654
    } The following table displays flow log attributes and their definitions: Log Attribute Definition timestamp Log generation time in epoch format. If required, this can be converted to human-readable log time in  MMM DD HH:mm:ss  format. flow_id Flow identifier. Unique within flow logs. flow_dir Direction of the flow: INCOMING—Flow originating at a remote site or the Internet and destined for the local LAN. OUTGOING—Flow originating at the local LAN and destined for a remote site, Internet, or cloud. LOCAL—Flow originating and terminating within the local LAN, routed through the ANAP. FLOW_DIR_HUB—Flow passing through this site, originating at one remote site and destined for another remote site.  setup_time Connection set up time in epoch format. If required, this can be converted to human-readable log time in  MMM DD HH:mm:ss  format. close_time Connection close time in epoch format. If required, this can be converted to human-readable log time in  MMM DD HH:mm:ss  format. src_ipv4 Source IP of the connection. dst_ipv4 Destination IP of the connection. src_port Source port of the connection. dst_port Destination port of the connection. protocol Protocol of the connection. src_zone Source zone from which the traffic originated. dst_zone Destination zone to which the traffic is destined: Public—Destination zone for internet traffic.  Cloud—Destination zone for cloud connector traffic.  VPN0, VPN1, and so on—Destination zone for remote site traffic. src_network Network from which the traffic originated with regard to the log’s originating site.  For example: LOCAL, VPN-ARYAKA, BOOSTNET, VPN-INTERNET, or PUBLIC dst_network Network to which the traffic is destined with regard to the log’s originating site. For example: LOCAL, VPN-ARYAKA, BOOSTNET, VPN-INTERNET, or PUBLIC isp1_wan_in Bytes received on the flow in the last interval using the primary ISP (ISP1). isp1_wan_out Bytes sent on the flow in the last interval using the primary ISP (ISP1). isp2_wan_in Bytes received on the flow in last interval using the secondary ISP (ISP2). isp2_wan_out Bytes sent on the flow in the last interval using the secondary ISP (ISP2). isp3_wan_in Bytes received on the flow in last interval using the tertiary ISP (ISP3). isp3_wan_out Bytes sent on the flow in the last interval using the tertiary ISP (ISP3). site_id Site identifier. domain_name Domain name used for the flow if there is a domain name associated with the connection. If there is no associated domain, this attribute is not included. Because traffic for a given flow logically traverses only one WAN interface, flow logs only include metrics for one of your ISPs (either ISP1, ISP2, or ISP3). Related topics SIEM Configure SIEM integration Monitor security