The Endpoint Security (HX) logs CEF messages when the agent on an endpoint host automatically performs malware remediation for detected malware. The CEF entries and fields logged vary based on the results of the malware remediation attempt.
CEF log entries are also written when a user attempts to delete or restore a file from the malware quarantine area. See Quarantine File User Action Log Fields . In addition, CEF log entries are written when a file ages out of the quarantine area. See Quarantine File Aging Log Fields
File quarantined and cleaned
When an infected file is automatically quarantined and cleaned, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:
Name: FireEye Quarantine Completed ID: FireEye Quarantine Completed act: Quarantine <host> Cleaned categoryTupleDescription: Quarantine task successfully completed, file cleaned.
File quarantined and deleted
When an infected file is automatically quarantined and deleted, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:
Name: FireEye Quarantine Completed ID: FireEye Quarantine Completed act: Quarantine <host> Quarantined categoryTupleDescription: Quarantine task successfully completed, file deleted.
File quarantined but not deleted
When an infected file is automatically quarantined but cannot be deleted, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:
Name: FireEye Quarantine Failed ID: FireEye Quarantine Failed act: Quarantine <host> Quarantined categoryTupleDescription: Quarantine task failed to complete.
Common malware remediation log fields
The following fields are common to all malware remediation CEF log entries.
cs3Label: Quarantine Action cs3: add cs4Label: Quarantine ID cs4: The unique ID for the quarantine cs5Label: Correlation ID cs5: The alert correlation ID. cs6Label: SHA1 cs6: The SHA1 hash of the quarantined file msg: Host <host> quarantine action filePath: The fully qualified file path of the quarantined and cleaned file fileHash: The file hash of the quarantined file name fsize: The size of the quarantined file start: Timestamp for the start of the remediation attempt on the destination host categoryOutcome: /Success categoryBehavior: /Access/Start categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: /Informational