AI Runtime Security API LEEF Fields
Focus
Focus
Strata Logging Service

AI Runtime Security API LEEF Fields

Table of Contents

AI Runtime Security API LEEF Fields

The following table identifies the AI Runtime Security API field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
Action
Custom
AgentFramework
Custom
AgentID
Custom
AIAppCloudProvider
Custom
AIAppCSPName
Custom
AIAppEnvironment
Custom
AIAppUserDomain
Custom
AIAppUserGroupID
Custom
AIAppUserGroupName
Custom
AIApplicationUserName
Custom
AIApplicationName
Custom
AIIncidentReportID
Custom
AIIncidentSubtype
Custom
AIIncidentType
Custom
AIModelName
Custom
AISecurityPolicyID
Custom
AISecurityPolicyName
Custom
AISecurityProfileID
Custom
AISecurityProfileName
Custom
AISubtypeDetails
Custom
APIKeyName
Custom
APIRegion
Custom
AppId
Custom
AssetID
Custom
CompletedTS
Custom
ContentMasked
Custom
ContentType
Custom
CSPID
Custom
s
Predefined
DetectionServiceFlags
Custom
FinalPromptAction
Custom
FinalPromptVerdict
Custom
FinalResponseAction
Custom
FinalResponseVerdict
Custom
IsCode
Custom
IsPrompt
Custom
IsPromptAgentRequested
Custom
IsPromptDLPRequested
Custom
IsPromptMCRequested
Custom
IsPromptPIRequested
Custom
IsPromptTCRequested
Custom
IsPromptTGRequested
Custom
IsPromptURLFRequested
Custom
IsResponse
Custom
IsResponseAgentRequested
Custom
IsResponseCGRequested
Custom
IsResponseDBSRequested
Custom
IsResponseDLPRequested
Custom
IsResponseMCRequested
Custom
IsResponseTCRequested
Custom
IsResponseTGRequested
Custom
IsResponseURLFRequested
Custom
Latency
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
MaxLatencyHit
Custom
MCPServer
Custom
PlatformType
Custom
RequestResponse
Custom
ScanID
Custom
ScanStartTime
Custom
ScanSUBRequestID
Custom
ScanType
Custom
SessionUrl
Custom
SubType
Custom
TextRecords
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
Tokens64
Custom
ToolName
Custom
TransactionID
Custom
TSGID
Custom
Vendor
Header
VendorSeverity
Custom
Verdict
Custom