<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which log format is best for syslog , CEF or LEEF in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261167#M74038</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say it really depends on your SIEM and what it can ingest better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2019 15:37:56 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-05-15T15:37:56Z</dc:date>
    <item>
      <title>Which log format is best for syslog , CEF or LEEF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261043#M73999</link>
      <description>&lt;P&gt;Anyone please explain the diference between CEF and LEEF and which one is best for 8.0.*.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 06:37:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261043#M73999</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-15T06:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Which log format is best for syslog , CEF or LEEF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261130#M74027</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="listbullet1"&gt;
&lt;LI class="listbullet1"&gt;&lt;SPAN class="guicharacter"&gt;LEEF &lt;/SPAN&gt;(Log Event Extended Format)—The LEEF event format is a proprietary event format, which allows hardware manufacturers and software product manufacturers to read and map device events specifically designed for IBM &lt;SPAN class="ph"&gt;QRadar&lt;/SPAN&gt; integration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="listbullet1"&gt;
&lt;LI class="listbullet1"&gt;&lt;SPAN class="guicharacter"&gt;CEF&lt;/SPAN&gt; (Common Event Format)—The CEF standard format is an open log management standard that simplifies log management. CEF allows third parties to create their own device schemas that are compatible with a standard thatis used industry-wide for normalizing security events.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wouldn't be able to tell you which one would be better over the other.&amp;nbsp; Maybe other users can help you make a better comparison between the 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're not using an IBM QRadar SIEM then I'm guessing that you will go with CEF &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 15 May 2019 13:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261130#M74027</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-15T13:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Which log format is best for syslog , CEF or LEEF</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261167#M74038</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say it really depends on your SIEM and what it can ingest better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 15:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/which-log-format-is-best-for-syslog-cef-or-leef/m-p/261167#M74038</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-15T15:37:56Z</dc:date>
    </item>
  </channel>
</rss>

