Glossary Term

Log Event Extended Format (LEEF)

IBM QRadar's structured event format for identifying a source and carrying security-event attributes that QRadar can process.

Definition

Log Event Extended Format is a customized event format for IBM QRadar. A LEEF record identifies the vendor, product, version, and event, then carries event attributes as key-value pairs. It may be sent through syslog or file collection.

For IBM i, a forwarding product can use LEEF to give QRadar a consistent event identity and fields. The team should still verify the time, user, object, job, result, and source-specific context after the record is normalized in QRadar.

Example

An IBM i forwarding tool may map a profile change to a stable LEEF event ID and include the affected profile, actor, system, and event time as attributes.