Common log fields

Prev Next

All CEF logs contain the following fields, in addition to fields for specific logs:

Time: Timestamp of log entry
Device Vendor: fireeye
Device Product: hx
Device Version: ADD LONG SW RELEASE
Name: A description of the logged event
ID: The same as Name value
Log Message Type:
0: Informational message
4: Warning message
7: Permanent acquisition error message
10: Any FireEye endpoint hit (alert), such as an IOC, malware, or exploit hit
             
rt: The time the event was recorded on the appliance
dvchost: Hostname of the Endpoint Security server
deviceExternalId: Appliance ID of the Endpoint Security server
cs1Label: Host Agent Cert Hash
cs1: The host agent certificate hash of the host generating the event
dst: The primary IP address of the host generating the event
dmac: The MAC address of the host generating the event
dhost: The name of the host generating the event
dntdom: The domain of the host generating the event
deviceCustomDate1Label: "Agent Last Sysinfo" or "Agent Last Audit"
deviceCustomDate1: Last system audit of the host generating the event
cs2Label: FireEye Agent Version
cs2: The version number of the agent on the host generating the event
cs5Label: Target GMT Offset, Correlation ID (remediation), or Actioned Objects Count (malware scans)
cs5: The GMT offset of the host generating the event in ISO 8601 duration format, the alert correlation ID for a malware quarantine attempt, or the number of scanned objects for which action is taken.
cs6Label: Target OS, SHA1 (remediation), or Scanned Objects Count (malware scans)
cs6: The operating system of the host generating the event, the SHA1 hash of the quarantined file, or the number of objects scanned for malware.
externalId: A reference number assigned to related events; events sharing the same ID should be considered connected
categoryOutcome: The agent outcome 
categorySignificance: The significance of the event
categoryBehavior: The agent behavior
cs7Label: Resolution
cs7: The result of the hit
cd8Label: Alert Types
cs8: The types of alert produced by the hit
msg: A text description of the event