Malware automatic remediation log fields

Prev Next

The Endpoint Security (HX) logs CEF messages when the agent on an endpoint host automatically performs malware remediation for detected malware. The CEF entries and fields logged vary based on the results of the malware remediation attempt.

CEF log entries are also written when a user attempts to delete or restore a file from the malware quarantine area. See Quarantine File User Action Log Fields . In addition, CEF log entries are written when a file ages out of the quarantine area. See Quarantine File Aging Log Fields

File quarantined and cleaned

When an infected file is automatically quarantined and cleaned, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:

Name: FireEye Quarantine Completed
ID: FireEye Quarantine Completed
act: Quarantine <host> Cleaned
categoryTupleDescription: Quarantine task successfully completed, file cleaned.

File quarantined and deleted

When an infected file is automatically quarantined and deleted, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:

Name: FireEye Quarantine Completed
ID: FireEye Quarantine Completed
act: Quarantine <host> Quarantined
categoryTupleDescription: Quarantine task successfully completed, file deleted.

File quarantined but not deleted

When an infected file is automatically quarantined but cannot be deleted, malware remediation logging includes the following fields and field settings, in addition to the common CEF fields and the common malware remediation CEF fields:

Name: FireEye Quarantine Failed
ID: FireEye Quarantine Failed
act: Quarantine <host> Quarantined
categoryTupleDescription: Quarantine task failed to complete.

Common malware remediation log fields

The following fields are common to all malware remediation CEF log entries.

cs3Label: Quarantine Action
cs3: add
cs4Label: Quarantine ID
cs4: The unique ID for the quarantine
cs5Label: Correlation ID
cs5: The alert correlation ID.
cs6Label: SHA1
cs6: The SHA1 hash of the quarantined file
msg: Host <host> quarantine action
filePath: The fully qualified file path of the quarantined and cleaned file
fileHash: The file hash of the quarantined file name
fsize: The size of the quarantined file
start: Timestamp for the start of the remediation attempt on the destination host
categoryOutcome: /Success
categoryBehavior: /Access/Start
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: /Informational