Strata Logging Service
Events LEEF Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
-
-
- Forward Logs to a Syslog Server
- Forward Logs to an HTTPS Server
- Forward Logs to an Email Server
- Forward Logs to Amazon Security Lake
- Forward Logs to AWS S3 Bucket
- Forward Logs to Snowflake
- Create Log Filters
- Server Certificate Validation
- List of Trusted Certificates for Syslog and HTTPS Forwarding
- Log Forwarding Errors
- Forward Logs With Log Replay
Events LEEF Fields
The following table identifies the Events field names that the Log Forwarding app
uses when you forward logs using the LEEF log format.
When you
create a syslog forwarding profile
,
you can optionally create a profile token that the Log
Forwarding app uses when it sends logs to the syslog server. If you configure a profile token,
it appears in the log line immediately after the log type information (for example,
TRAFFIC, THREAT,
HIPMATCH, and so forth). The token will appear on
a parameter called profileToken.
LEEF Name
|
Query Name
|
Field Type
|
---|---|---|
ApplicationAppCategory
|
Custom
| |
ApplicationAppSubcategory
|
Custom
| |
ApplicationExternalID
|
Custom
| |
ApplicationExternalName
|
Custom
| |
ApplicationID
|
Custom
| |
ApplicationName
|
Custom
| |
ApplicationProtectedAccount
|
Custom
| |
ApplicationRiskOfApp
|
Custom
| |
ApplicationSource
|
Custom
| |
ApplicationUsername
|
Custom
| |
BatchID
|
Custom
| |
BrowserExtensionAppLaunchURL
|
Custom
| |
BrowserExtensionAvailableLaunchTypes
|
Custom
| |
BrowserExtensionDescription
|
Custom
| |
BrowserExtensionDisabledReason
|
Custom
| |
BrowserExtensionEnabled
|
Custom
| |
BrowserExtensionHomepageURL
|
Custom
| |
BrowserExtensionHostPermissions
|
Custom
| |
BrowserExtensionID
|
Custom
| |
BrowserExtensionInstallType
|
Custom
| |
BrowserExtensionIsApp
|
Custom
| |
BrowserExtensionLaunchType
|
Custom
| |
BrowserExtensionMayDisable
|
Custom
| |
BrowserExtensionName
|
Custom
| |
BrowserExtensionOfflineEnabled
|
Custom
| |
BrowserExtensionOptionsURL
|
Custom
| |
BrowserExtensionPermissions
|
Custom
| |
BrowserExtensionShortName
|
Custom
| |
BrowserExtensionType
|
Custom
| |
BrowserExtensionUpdateURL
|
Custom
| |
BrowserExtensionVersion
|
Custom
| |
CertificateCreatedTime
|
Custom
| |
CertificateExpirationTime
|
Custom
| |
CertificateFingerprints
|
Custom
| |
CertificateIssuer
|
Custom
| |
CertificateSerialNumber
|
Custom
| |
CertificateSubject
|
Custom
| |
ClassificationCategory
|
Custom
| |
ClassificationMaliciousCategories
|
Custom
| |
ClassificationMITRE
|
Custom
| |
ClassificationReputation
|
Custom
| |
ClassificationSecurityCompliance
|
Custom
| |
ClassificationSeverity
|
Custom
| |
ClipboardFromURL
|
Custom
| |
ClipboardSelectedElement
|
Custom
| |
ContentCategories
|
Custom
| |
ContentLengthBytes
|
Custom
| |
ContentMIPMatchedLabel
|
Custom
| |
ContentScanEngine
|
Custom
| |
ContentSensitiveDataCategories
|
Custom
| |
ContentSourceElementSelector
|
Custom
| |
ContentSourceURL
|
Custom
| |
CortexDataLakeTenantID
|
Custom
| |
DeviceBrowserBrand
|
Custom
| |
DeviceBrowserType
|
Custom
| |
DeviceBrowserVersion
|
Custom
| |
DeviceUUID
|
Custom
| |
DeviceDiskEncryptionStatus
|
Custom
| |
DeviceEPPStatus
|
Custom
| |
DeviceExtensionVersion
|
Custom
| |
DeviceFirewallStatus
|
Custom
| |
DeviceGeoIPFromCityName
|
Custom
| |
DeviceGeoIPFromCountryName
|
Custom
| |
DeviceGeoIPFromLocationLatitude
|
Custom
| |
DeviceGeoIPFromLocationLongitude
|
Custom
| |
DeviceGroupsIDs
|
Custom
| |
DeviceGroupsNames
|
Custom
| |
DeviceHostname
|
Custom
| |
DeviceIPAddress
|
Custom
| |
DeviceMACAddresses
|
Custom
| |
DeviceModel
|
Custom
| |
DeviceOSAndroidBuild
|
Custom
| |
DeviceOSAndroidPatch
|
Custom
| |
DeviceOSAndroidRelease
|
Custom
| |
DeviceOSAndroidSDK
|
Custom
| |
DeviceOSiOSMajor
|
Custom
| |
DeviceOSiOSMinor
|
Custom
| |
DeviceOSiOSPatch
|
Custom
| |
DeviceOSmacOSBugfix
|
Custom
| |
DeviceOSmacOSBuild
|
Custom
| |
DeviceOSmacOSMajor
|
Custom
| |
DeviceOSmacOSMinor
|
Custom
| |
DeviceOSmacOSServer
|
Custom
| |
DeviceOSType
|
Custom
| |
DeviceOSWindowsBuild
|
Custom
| |
DeviceOSWindowsMajor
|
Custom
| |
DeviceOSWindowsMinor
|
Custom
| |
DeviceOSWindowsPatch
|
Custom
| |
DeviceOSWindowsProduct
|
Custom
| |
DeviceOSDisplayName
|
Custom
| |
DeviceRawUniversalID
|
Custom
| |
DeviceScreenLockStatus
|
Custom
| |
DeviceSerialNumber
|
Custom
| |
DeviceType
|
Custom
| |
DeviceUserAgent
|
Custom
| |
FileExtension
|
Custom
| |
FileIsEncrypted
|
Custom
| |
FileLocalPath
|
Custom
| |
FileMimeType
|
Custom
| |
FileName
|
Custom
| |
FileOperation
|
Custom
| |
FileOriginDownloadURL
|
Custom
| |
FileSHA256
|
Custom
| |
FileURL
|
Custom
| |
ID
|
Custom
| |
LogSource
|
Custom
| |
LogSourceGroupID
|
Custom
| |
DeviceSN
|
Custom
| |
DeviceName
|
Custom
| |
TimeReceived
|
Custom
| |
cat
|
Predefined
| |
NetworkClassifications
|
Custom
| |
NetworkFrameURL
|
Custom
| |
NetworkHTTPMethod
|
Custom
| |
NetworkHTTPStatus
|
Custom
| |
NetworkProtocol
|
Custom
| |
NetworkTabURL
|
Custom
| |
NetworkURL
|
Custom
| |
PageCaptureIsSecureScreenshot
|
Custom
| |
PageCaptureTriggeredByURL
|
Custom
| |
PageDevtoolsBlockReason
|
Custom
| |
PageTitle
|
Custom
| |
PincodeFailedAttempts
|
Custom
| |
PincodeRegistrationTime
|
Custom
| |
PlatformType
|
Custom
| |
PolicyAction
|
Custom
| |
PolicyBlockReason
|
Custom
| |
PolicyBypassReason
|
Custom
| |
PolicyIsMonitor
|
Custom
| |
PolicyIsSessionRecorded
|
Custom
| |
PolicyRuleDescription
|
Custom
| |
PolicyRuleID
|
Custom
| |
PostureBlockReason
|
Custom
| |
PostureBlockType
|
Custom
| |
PostureError
|
Custom
| |
PrintPrinterLocation
|
Custom
| |
PrintPrinterName
|
Custom
| |
ProcessCLIArgs
|
Custom
| |
ProcessImagePath
|
Custom
| |
ProcessParentProcess
|
Custom
| |
ProcessPID
|
Custom
| |
StateDeviceGroupEvaluation
|
Custom
| |
StateSignInRules
|
Custom
| |
SubtenantID
|
Custom
| |
Subtype
|
Custom
| |
TamperingType
|
Custom
| |
TenantID
|
Custom
| |
devTime
|
Predefined
| |
TimeGeneratedHighResolution
|
Custom
| |
Timestamp
|
Custom
| |
TSGID
|
Custom
| |
Type
|
Custom
| |
UserEmail
|
Custom
| |
UserExternalID
|
Custom
| |
UserGroupsIDs
|
Custom
| |
UserGroupsNames
|
Custom
| |
UserID
|
Custom
| |
UserName
|
Custom
| |
UserTenantExternalID
|
Custom
| |
UserTenantID
|
Custom
| |
UserTenantName
|
Custom
| |
UserTSGID
|
Custom
| |
Vendor
|
Header
|