Audit LEEF Fields
Focus
Focus
Strata Logging Service

Audit LEEF Fields

Table of Contents

Audit LEEF Fields

The following table identifies the Audit field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example,
TRAFFIC
,
THREAT
,
HIPMATCH
, and so forth). The token will appear on a parameter called
profileToken
.
LEEF Name
Query Name
Field Type
Event Category
Custom
Event Description
Custom
Event Destination URL
Custom
Destination Vendor
Custom
Event Details
Custom
Event Name
Custom
Event Result
Custom
Event Time
Custom
Log Source
Custom
LogSourceGroupID
Custom
Log Source ID
Custom
Log Time
Custom
Log Type
Custom
PlatformType
Custom
Subtype
Custom
Vendor Name
Custom
Vendor Severity
Custom

Recommended For You