Scan Event LEEF Fields
Focus
Focus
Strata Logging Service

Scan Event LEEF Fields

Table of Contents

Scan Event LEEF Fields

The following table identifies the Scan Event field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
CreatedBy
Custom
CortexDataLakeTenantID
Custom
EnabledRuleCount
Custom
ErrorCode
Custom
ErrorMessage
Custom
EvalOutcome
Custom
Labels
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
ModelAuthor
Custom
ModelFormats
Custom
ModelName
Custom
ModelURI
Custom
ModelVersion
Custom
PlatformType
Custom
RuleFailedCount
Custom
RulePassedCount
Custom
ScanOrigin
Custom
ScanUUID
Custom
ScannerVersion
Custom
SDKVersion
Custom
SecurityGroupName
Custom
SecurityGroupUUID
Custom
SourceType
Custom
SubType
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
TimeStarted
Custom
TotalFilesScanned
Custom
TotalFilesSkipped
Custom
TSGID
Custom
Vendor
Header
ViolationCount
Custom
Violations
Custom