Management LEEF Fields
Focus
Focus
Strata Logging Service

Management LEEF Fields

Table of Contents

Management LEEF Fields

The following table identifies the Management field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
AttemptedGateways
Custom
AuthMethod
Custom
ConfigVersion
Custom
ConnectionMethod
Custom
ConnectionErrorID
Custom
ConnectionError
Custom
CountOfRepeats
Custom
TenantID
Custom
DGHierarchyLevel1
Custom
DGHierarchyLevel2
Custom
DGHierarchyLevel3
Custom
DGHierarchyLevel4
Custom
EndpointDeviceName
Custom
ZTNAClientVersion
Custom
EndpointOSType
Custom
EndpointOSVersion
Custom
EndpointSN
Custom
EventID
Header
Gateway
Custom
GatewayPriority
Custom
GatewaySelectionType
Custom
ZTNAGatewayLocation
Custom
HostID
Custom
IsDuplicateLog
Custom
LogExported
Custom
LogForwarded
Custom
IsPrismaNetworks
Custom
IsPrismaUsers
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
LoginDuration
Custom
Description
Custom
PanoramaSN
Custom
PlatformType
Custom
Portal
Custom
PrivateIPv4
Custom
PrivateIPv6
Custom
ProjectName
Custom
PublicIPv4
Custom
PublicIPv6
Custom
QuarantineReason
Custom
SequenceNo
Custom
SourceRegion
Custom
usrName
Predefined
SourceUserInfoDomain
Custom
SourceUserInfoName
Custom
SourceUserInfoUUID
Custom
SSLResponseTime
Custom
Stage
Custom
EventStatus
Custom
SubType
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
TunnelType
Custom
Vendor
Header
VirtualSystem
Custom
VirtualSystemID
Custom
VirtualSystemName
Custom