SD-WAN Traffic LEEF Fields
Focus
Focus
Strata Logging Service

SD-WAN Traffic LEEF Fields

Table of Contents

SD-WAN Traffic LEEF Fields

The following table identifies the SD-WAN Traffic field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
Action
Custom
Application
Custom
ApplicationCategory
Custom
ApplicationSubcategory
Custom
dstBytes
Predefined
srcBytes
Predefined
ApplicationCharacteristics
Custom
ApplicationContainer
Custom
CortexDataLakeTenantId
Custom
DestinationIP
Custom
dstPort
Predefined
DestinationUserInfoDomain
Custom
DestinationUserInfoName
Custom
DestinationUserInfoUUID
Custom
FromZone
Custom
InboundInterface
Custom
IsClienttoServer
Custom
IsIPV6
Custom
IsSaaSApplication
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
EgressInterface
Custom
dstPackets
Predefined
srcPackets
Predefined
PathValue
Custom
PathLabel
Custom
PlatformType
Custom
SDWANElementId
Custom
SDWANElementName
Custom
SDWANSiteId
Custom
SDWANSiteName
Custom
SDWANTenantId
Custom
proto
Predefined
ApplicationRisk
Custom
SecurityRule
Custom
RuleUUID
Custom
SanctionedStateOfApp
Custom
SessionEndReason
Custom
SessionID
Custom
SessionStartTime
Custom
SourceDeviceCategory
Custom
SourceDeviceClass
Custom
SourceDeviceHost
Custom
SourceDeviceMac
Custom
SourceDeviceModel
Custom
SourceDeviceOS
Custom
SourceDeviceOSFamily
Custom
SourceDeviceOSVersion
Custom
SourceDeviceProfile
Custom
SourceDeviceVendor
Custom
src
Predefined
srcPort
Predefined
UsrName
Custom
SourceUserInfoDomain
Custom
SourceUserInfoName
Custom
SourceUserInfoUUID
Custom
SubType
Custom
ApplicationTechnology
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
ToZone
Custom
SessionDuration
Custom
TrafficClass
Custom
TSGID
Custom
URLCategory
Custom
Vendor
Header