tenzir-leef

Installation
SKILL.md

Log Event Extended Format

LEEF (Log Event Extended Format) is IBM's event format for QRadar. A LEEF event is a single line consisting of an optional syslog header, a pipe-delimited LEEF header, and a flat list of key=value event attributes.

The latest LEEF version is 2.0, which this skill documents. LEEF 2.0 adds one optional header field to LEEF 1.0: a delimiter character for the event attributes. Both header layouts are covered in LEEF event components.

Use attributes.yaml as the authoritative reference for the predefined event attributes: exact key spelling, value type, normalization behavior, limits, and reserved status. If an attribute is not present there, it is not a predefined LEEF attribute.

Data files

Format rules

Installs
17
Repository
tenzir/skills
GitHub Stars
3
First Seen
Jun 13, 2026
tenzir-leef — tenzir/skills