The Endpoint Security (HX) can retain Common Event Format (CEF) traffic containing information about hits (alerts), acquisition requests, triage collections, and containment activity.
Because retaining such entries in local logging can cause the /var/log/messages file to fill quickly, Endpoint Security (HX) suppresses these entries by default to optimize performance. If your enterprise is integrating Endpoint Security (HX) with a SIEM solution, your enterprise can configure CEF logging settings. See the Endpoint Security (HX) System Administration Guide for more information.
This section details common and specific Endpoint Security (HX) CEF logging events and event activity fields that can be retained and exported to SIEM solutions.