AI Security LEEF Fields
Focus
Focus
Strata Logging Service

AI Security LEEF Fields

Table of Contents

AI Security LEEF Fields

The following table identifies the AI Security field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
EventID
Header
AIIncidentReportID
Custom
AIIncidentSubtype
Custom
AIIncidentType
Custom
AIModelCSPName
Custom
AIModelCSPRegionName
Custom
AIModelName
Custom
AISecurityProfileName
Custom
AISubtypeDetails
Custom
CortexDataLakeTenantID
Custom
dst
Predefined
dstPort
Predefined
KubernetesClusterID
Custom
Latency
Custom
LogSource
Custom
DeviceSN
Custom
DeviceName
Custom
TimeReceived
Custom
cat
Predefined
MaxLatencyHit
Custom
PlatformType
Custom
Protocol
Custom
ThreatinRequestorResponse
Custom
SessionID
Custom
SessionStartTime
Custom
src
Predefined
srcPort
Predefined
TimeGenerated
Custom
TimeGeneratedHighResolution
Custom
TSGID
Custom
Vendor
Header
VendorSeverity
Custom