Directory sync LEEF Fields
Focus
Focus
Strata Logging Service

Directory sync LEEF Fields

Table of Contents

Directory sync LEEF Fields

The following table identifies the Directory sync field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
CIETimeReceived
Custom
ClientApplicationId
Custom
Count
Custom
CountSummaryApplication
Custom
CountSummaryComputer
Custom
CountSummaryContainer
Custom
CountSummaryGroup
Custom
CountSummaryOU
Custom
CountSummar RoleAssignments
Custom
CountSummaryUser
Custom
s
Predefined
DirectoryId
Custom
DirectoryName
Custom
DirectoryType
Custom
EventCategory
Custom
EventSequenceId
Custom
EventState
Custom
EventType
Custom
FailureReasonCode
Custom
FlattenedMembershipCountCIE
Custom
FlattenedMembershipCountCIEPreviousSync
Custom
FlattenedMembershipCountIDP
Custom
ImmediateMembershipCountCIE
Custom
ImmediateMembershipCountCIEPreviousSync
Custom
ImmediateMembershipCountIDP
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
PlatformType
Custom
RecommendedAction
Custom
SourceId
Custom
SourceType
Custom
SubType
Custom
SyncJobId
Custom
SyncType
Custom
TargetId
Custom
TargetType
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
TSGID
Custom
Vendor
Header