Hi,
It's a good question. Wasn't involved in the mapping, but from IBM's description think it makes sense to map action to cat as to extend EventID with additional information about the event. It may also get mapped to EventID. In the header we map product and EventID like this.
Product: the assign_order is set to first
This default is Log Update, but may also be the value from the fields; product or productname.
Event ID, the assign_order is set to init
The default is Check Point Log, but may also be the value from the fields protection_name, appi_name, action.
Expect the end result would be something like their Example 1.
https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_LEEF_Format_Guide_predefinedAttrrs.html