Audit LEEF Fields
Focus
Focus
Strata Logging Service

Audit LEEF Fields

Table of Contents

Audit LEEF Fields

The following table identifies the Audit field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
EventCategory
Custom
EventDescription
Custom
EventDestinationURL
Custom
EventDestinationUserUserID
Custom
DestinationVendor
Custom
EventDetails
Custom
EventID
Header
EventName
Custom
EventResult
Custom
EventSourceUserUserID
Custom
EventTime
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
TimeReceived
Custom
cat
Predefined
PlatformType
Custom
Subtype
Custom
TSGID
Custom
Vendor
Header
VendorSeverity
Custom