Containment action log fields

Prev Next

The Endpoint Security (HX) logs messages when containment is requested, enabled, and removed from a destination host.

Containment Requested

When containment is requested, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Requested
ID: FireEye Containment Requested
act: Containment Requested
request: URL to destination host in HX
suser: User name requesting containment
msg: Host <hostname> containment requested by <user>

Containment Request Cancelled

When a containment request is cancelled, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Cancelled
ID: FireEye Containment cancelled
act: Containment Request Cancelled
request: URL to destination host in HX
suser: User name approving the stop containment request
msg: Host <hostname> containment request cancelled by <user>

Containment Approved

When containment is approved, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Approved
ID: FireEye Containment Approved
act: Containment Approved
request: URL to destination host in HX
suser: User name approving containment
msg: Host <hostname> containment approved by <user>

Containment Queued

When containment is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

This indicates the start of servicing of a containment request.

Name: FireEye Containment Queued
ID: FireEye Containment Queued
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: contain
msg: Host <hostname ><action> queued

Containment Started

When containment is started, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Started
ID: FireEye Containment Started
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: contain
msg: Host <hostname> <action> started

Containment Completed

When containment completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Completed
ID: FireEye Containment Completed
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: contain
msg: Hostname <hostname> <action> completed

Containment Error

When an error occurs for a containment request because containment is not enabled, the host is excluded from the containment set, or because an invalid upgrade version is encountered, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Error
ID: FireEye Containment Error
act: Containment Status
request: URL to destination host in HX
suser: User name associated with the containment request
msg: Host <hostname> <action> failed

Containment Failed

When a containment request fails because an error occurs retrieving payloads, the results are in an improper output format, or because the result returned an unexpected containment state, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Failed
ID: FireEye Containment Failed
act: Containment Status
request: URL to destination host in HX
suser: User name associated with the containment request
msg: Host <hostname> <action> failed

Containment Aborted

When a containment request task is aborted, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Aborted
ID: FireEye Containment Aborted
act: Containment Status
request: URL to destination host in HX
suser: User name associated with the containment request
msg: Host <hostname> <action> aborted

Uncontainment Initialized

When an attempt to remove a host from containment is initialized, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Hidden because of ENDPT-2600 -- but keeping this in case there is a problem.

Name: FireEye Uncontain Initialized
ID: FireEye Uncontain Started
act: Uncontain Initialized
request: URL to destination host in HX
suser: User name initializing the containment stop (uncontainment)

Uncontainment Approved

When an attempt to remove a host from containment is approved, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Stop Containment Approval
ID: FireEye Containment Started
act: Stop Containment Approved
request: URL to destination host in HX
suser: User name approving the stop containment request
msg: Host <hostname> stop containment approved by <user>

Uncontainment Queued

When an attempt to remove a host from containment is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Queued
ID: FireEye Containment Queued
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: uncontain
msg: Host <hostname ><action> queued

Uncontainment Started

When an attempt to remove a host from containment is initialized, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Started
ID: FireEye Containment Started
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: uncontain
msg: Host <hostname ><action> started

Uncontainment Completed

When an attempt to remove a host from containment completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Completed
ID: FireEye Containment Completed
act: Containment Status
request: URL to destination host in HX
cs3Label: Containment action
cs3: uncontain
msg: Host <hostname ><action> completed

Uncontainment Aborted

When an uncontainment request task is aborted, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:

Name: FireEye Containment Aborted
ID: FireEye Containment Aborted
act: Containment Status
request: URL to destination host in HX
suser: User name associated with the containment request
msg: Host <hostname> <action> aborted

Common Containment Log Fields

The following fields are common to all containment and uncontainment CEF log entries.

cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
categoryBehavior: /Create (for Requested, Approved, Created, Queued, Started), /Access/Start (for Completed)
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categoryOutcome: /Success/Failure
categorySignificance: /Informational/Error
categoryTupleDescription: A description of the event