The Endpoint Security (HX) logs messages when containment is requested, enabled, and removed from a destination host.
Containment Requested
When containment is requested, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Requested ID: FireEye Containment Requested act: Containment Requested request: URL to destination host in HX suser: User name requesting containment msg: Host <hostname> containment requested by <user>
Containment Request Cancelled
When a containment request is cancelled, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Cancelled ID: FireEye Containment cancelled act: Containment Request Cancelled request: URL to destination host in HX suser: User name approving the stop containment request msg: Host <hostname> containment request cancelled by <user>
Containment Approved
When containment is approved, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Approved ID: FireEye Containment Approved act: Containment Approved request: URL to destination host in HX suser: User name approving containment msg: Host <hostname> containment approved by <user>
Containment Queued
When containment is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
This indicates the start of servicing of a containment request.
Name: FireEye Containment Queued ID: FireEye Containment Queued act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: contain msg: Host <hostname ><action> queued
Containment Started
When containment is started, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Started ID: FireEye Containment Started act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: contain msg: Host <hostname> <action> started
Containment Completed
When containment completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Completed ID: FireEye Containment Completed act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: contain msg: Hostname <hostname> <action> completed
Containment Error
When an error occurs for a containment request because containment is not enabled, the host is excluded from the containment set, or because an invalid upgrade version is encountered, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Error ID: FireEye Containment Error act: Containment Status request: URL to destination host in HX suser: User name associated with the containment request msg: Host <hostname> <action> failed
Containment Failed
When a containment request fails because an error occurs retrieving payloads, the results are in an improper output format, or because the result returned an unexpected containment state, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Failed ID: FireEye Containment Failed act: Containment Status request: URL to destination host in HX suser: User name associated with the containment request msg: Host <hostname> <action> failed
Containment Aborted
When a containment request task is aborted, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Aborted ID: FireEye Containment Aborted act: Containment Status request: URL to destination host in HX suser: User name associated with the containment request msg: Host <hostname> <action> aborted
Uncontainment Initialized
When an attempt to remove a host from containment is initialized, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Hidden because of ENDPT-2600 -- but keeping this in case there is a problem.
Name: FireEye Uncontain Initialized ID: FireEye Uncontain Started act: Uncontain Initialized request: URL to destination host in HX suser: User name initializing the containment stop (uncontainment)
Uncontainment Approved
When an attempt to remove a host from containment is approved, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Stop Containment Approval ID: FireEye Containment Started act: Stop Containment Approved request: URL to destination host in HX suser: User name approving the stop containment request msg: Host <hostname> stop containment approved by <user>
Uncontainment Queued
When an attempt to remove a host from containment is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Queued ID: FireEye Containment Queued act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: uncontain msg: Host <hostname ><action> queued
Uncontainment Started
When an attempt to remove a host from containment is initialized, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Started ID: FireEye Containment Started act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: uncontain msg: Host <hostname ><action> started
Uncontainment Completed
When an attempt to remove a host from containment completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Completed ID: FireEye Containment Completed act: Containment Status request: URL to destination host in HX cs3Label: Containment action cs3: uncontain msg: Host <hostname ><action> completed
Uncontainment Aborted
When an uncontainment request task is aborted, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common containment fields:
Name: FireEye Containment Aborted ID: FireEye Containment Aborted act: Containment Status request: URL to destination host in HX suser: User name associated with the containment request msg: Host <hostname> <action> aborted
Common Containment Log Fields
The following fields are common to all containment and uncontainment CEF log entries.
cs5Label: Target GMT Offset cs5: The GMT offset of the host generating the event in ISO 8601 duration format cs6Label: Target OS cs6: The operating system of the host generating the event categoryBehavior: /Create (for Requested, Approved, Created, Queued, Started), /Access/Start (for Completed) categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categoryOutcome: /Success/Failure categorySignificance: /Informational/Error categoryTupleDescription: A description of the event