AI Conversation Log LEEF Fields
Focus
Focus
Strata Logging Service

AI Conversation Log LEEF Fields

Table of Contents

AI Conversation Log LEEF Fields

The following table identifies the AI Conversation Log field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
Action
Custom
AppClassification
Custom
AppID
Custom
AppName
Custom
Channel
Custom
Content
Custom
ContentExtracted
Custom
ConversationID
Custom
CortexDataLakeTenantID
Custom
DataSize
Custom
DLPDataProfiles
Custom
DLPIncidentID
Custom
DLPTenantID
Custom
FileName
Custom
FileType
Custom
IsFileBased
Custom
IsPrompt
Custom
IsResponse
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
PlatformType
Custom
PromptIntents
Custom
PromptTopics
Custom
ReportID
Custom
ScanRegion
Custom
SessionKey
Custom
Snippets
Custom
Source
Custom
SubType
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
TSGID
Custom
URL
Custom
UserID
Custom
Vendor
Header
DLPVerdict
Custom