Indicator hit detection log fields

Prev Next

The Endpoint Security (HX) logs messages when indicator of compromise (IOC) rules are found on a destination host. In addition to the common CEF fields, indicator hit detection logging includes the following fields and field settings:

IOC hit detection

Name: IOC Hit Found
ID: IOC Hit Found
cs4Label: IOC Name
cs4: Name of the HX threat that was found on the destination host
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
act: Detection IOC Hit
externalId: The HX unique identifier associated with this hit
start: Timestamp when the indicator was detected on the destination host
categoryOutcome: /Success
categoryBehavior: /Found
categoryDeviceGroup: /IDS
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: /Compromise
categoryTechnique: Alert
categoryTupleDescription: A Detection IOC found a compromise indication
msg: Host <hostname> IOC compromise