The Endpoint Security (HX) logs messages when indicator of compromise (IOC) rules are found on a destination host. In addition to the common CEF fields, indicator hit detection logging includes the following fields and field settings:
IOC hit detection
Name: IOC Hit Found ID: IOC Hit Found cs4Label: IOC Name cs4: Name of the HX threat that was found on the destination host cs5Label: Target GMT Offset cs5: The GMT offset of the host generating the event in ISO 8601 duration format cs6Label: Target OS cs6: The operating system of the host generating the event act: Detection IOC Hit externalId: The HX unique identifier associated with this hit start: Timestamp when the indicator was detected on the destination host categoryOutcome: /Success categoryBehavior: /Found categoryDeviceGroup: /IDS categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: /Compromise categoryTechnique: Alert categoryTupleDescription: A Detection IOC found a compromise indication msg: Host <hostname> IOC compromise