

I have a rule that alerts me when we have a failed login on our firewall. I would like to have it list the public IP address that attempted to login. Palo Alto keeps this information, so I should be able to find a rule ID for this, but I cant seem to find it anywhere. Any help would be appreciated! Host: is my devices IP address, but I would like to add a field for the public IP of the attempt.
Thanks!