Palo Alto Prisma access pan-0S 9.1 GLOBALPROTECT type cef mapping

Hello,

I need to collect logs from PAN Prisma Access (formerly GlobalProtect cloud service) PAN-OS 9.1
A client send me a sample log file collected via syslog (not CEF formatted)

These client's logs contains these 5 type of log:

Traffic Log Fields
HIP Match Log Fields
GlobalProtect Log Fields
User-ID Log Fields
System Log Fields

(The complete list is this: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions.html

Traffic Log Fields
Threat Log Fields
HIP Match Log Fields
GlobalProtect Log Fields
IP-Tag Log Fields
User-ID Log Fields
Tunnel Inspection Log Fields
SCTP Log Fields
Config Log Fields
Authentication Log Fields
System Log Fields
Correlated Events Log Fields
GTP Log Fields
Custom Log/Event Format
Escape Sequences)

In the document "Palo Alto Networks PAN-OS 9.1 Integration Guide 9.1" published  in marketplace:

https://marketplace.microfocus.com/arcsight/content/palo-alto-networks-next-generation-firewalls

I find the cef mapping format for the "TRAFFIC", "HIPMATCH", "USERID" and "SYSTEM" but can not find the cef mapping for the "GLOBALPROTECT" type.
Is this TYPE group missing in the document or is mapped in some other TYPES?

Thanks ,

Roby

aaaa.jpg