Events LEEF Fields
Focus
Focus
Strata Logging Service

Events LEEF Fields

Table of Contents

Events LEEF Fields

The following table identifies the Events field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
ApplicationAppCategory
Custom
ApplicationAppSubcategory
Custom
ApplicationExternalID
Custom
ApplicationExternalName
Custom
ApplicationID
Custom
ApplicationName
Custom
ApplicationProtectedAccount
Custom
ApplicationRiskOfApp
Custom
ApplicationSource
Custom
ApplicationUsername
Custom
BatchID
Custom
BrowserExtensionAppLaunchURL
Custom
BrowserExtensionAvailableLaunchTypes
Custom
BrowserExtensionDescription
Custom
BrowserExtensionDisabledReason
Custom
BrowserExtensionEnabled
Custom
BrowserExtensionHomepageURL
Custom
BrowserExtensionHostPermissions
Custom
BrowserExtensionID
Custom
BrowserExtensionInstallType
Custom
BrowserExtensionIsApp
Custom
BrowserExtensionLaunchType
Custom
BrowserExtensionMayDisable
Custom
BrowserExtensionName
Custom
BrowserExtensionOfflineEnabled
Custom
BrowserExtensionOptionsURL
Custom
BrowserExtensionPermissions
Custom
BrowserExtensionShortName
Custom
BrowserExtensionType
Custom
BrowserExtensionUpdateURL
Custom
BrowserExtensionVersion
Custom
CertificateCreatedTime
Custom
CertificateExpirationTime
Custom
CertificateFingerprints
Custom
CertificateIssuer
Custom
CertificateSerialNumber
Custom
CertificateSubject
Custom
ClassificationCategory
Custom
ClassificationMaliciousCategories
Custom
ClassificationMITRE
Custom
ClassificationReputation
Custom
ClassificationSecurityCompliance
Custom
ClassificationSeverity
Custom
ClipboardFromURL
Custom
ClipboardSelectedElement
Custom
ContentCategories
Custom
ContentLengthBytes
Custom
ContentMIPMatchedLabel
Custom
ContentScanEngine
Custom
ContentSensitiveDataCategories
Custom
ContentSourceElementSelector
Custom
ContentSourceURL
Custom
CortexDataLakeTenantID
Custom
DeviceBrowserBrand
Custom
DeviceBrowserType
Custom
DeviceBrowserVersion
Custom
DeviceUUID
Custom
DeviceDiskEncryptionStatus
Custom
DeviceEPPStatus
Custom
DeviceExtensionVersion
Custom
DeviceFirewallStatus
Custom
DeviceGeoIPFromCityName
Custom
DeviceGeoIPFromCountryName
Custom
DeviceGeoIPFromLocationLatitude
Custom
DeviceGeoIPFromLocationLongitude
Custom
DeviceGroupsIDs
Custom
DeviceGroupsNames
Custom
DeviceHostname
Custom
DeviceIPAddress
Custom
DeviceMACAddresses
Custom
DeviceModel
Custom
DeviceOSAndroidBuild
Custom
DeviceOSAndroidPatch
Custom
DeviceOSAndroidRelease
Custom
DeviceOSAndroidSDK
Custom
DeviceOSiOSMajor
Custom
DeviceOSiOSMinor
Custom
DeviceOSiOSPatch
Custom
DeviceOSmacOSBugfix
Custom
DeviceOSmacOSBuild
Custom
DeviceOSmacOSMajor
Custom
DeviceOSmacOSMinor
Custom
DeviceOSmacOSServer
Custom
DeviceOSType
Custom
DeviceOSWindowsBuild
Custom
DeviceOSWindowsMajor
Custom
DeviceOSWindowsMinor
Custom
DeviceOSWindowsPatch
Custom
DeviceOSWindowsProduct
Custom
DeviceOSDisplayName
Custom
DeviceRawUniversalID
Custom
DeviceScreenLockStatus
Custom
DeviceSerialNumber
Custom
DeviceType
Custom
DeviceUserAgent
Custom
FileExtension
Custom
FileIsEncrypted
Custom
FileLocalPath
Custom
FileMimeType
Custom
FileName
Custom
FileOperation
Custom
FileOriginDownloadURL
Custom
FileSHA256
Custom
FileURL
Custom
ID
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
TimeReceived
Custom
cat
Predefined
NetworkClassifications
Custom
NetworkFrameURL
Custom
NetworkHTTPMethod
Custom
NetworkHTTPStatus
Custom
NetworkProtocol
Custom
NetworkTabURL
Custom
NetworkURL
Custom
PageCaptureIsSecureScreenshot
Custom
PageCaptureTriggeredByURL
Custom
PageDevtoolsBlockReason
Custom
PageTitle
Custom
PincodeFailedAttempts
Custom
PincodeRegistrationTime
Custom
PlatformType
Custom
PolicyAction
Custom
PolicyBlockReason
Custom
PolicyBypassReason
Custom
PolicyIsMonitor
Custom
PolicyIsSessionRecorded
Custom
PolicyRuleDescription
Custom
PolicyRuleID
Custom
PostureBlockReason
Custom
PostureBlockType
Custom
PostureError
Custom
PrintPrinterLocation
Custom
PrintPrinterName
Custom
ProcessCLIArgs
Custom
ProcessImagePath
Custom
ProcessParentProcess
Custom
ProcessPID
Custom
StateDeviceGroupEvaluation
Custom
StateSignInRules
Custom
SubtenantID
Custom
Subtype
Custom
TamperingType
Custom
TenantID
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
Timestamp
Custom
TSGID
Custom
Type
Custom
UserEmail
Custom
UserExternalID
Custom
UserGroupsIDs
Custom
UserGroupsNames
Custom
UserID
Custom
UserName
Custom
UserTenantExternalID
Custom
UserTenantID
Custom
UserTenantName
Custom
UserTSGID
Custom
Vendor
Header