Malware false positive log fields

Prev Next

The Endpoint Security (HX) logs messages when malware is marked as false positive and when it is changed back to true positive. In addition to the common CEF fields, malware false positive logging includes the following fields and field settings.

DTI-marked false positive:

Name: FireEye False Positive Updated
ID: FireEye False Positive Updated
cs1Label: False Positive action (differs from the common CEF fields)
cs1: mark_false_positive (differs from the common CEF fields)
cs2Label: condition (differs from the common CEF fields)
cs2: <condition that was marked false positive> (differs from the common CEF fields)
act: False Positive
externalId: The HX unique identifier associated with the false positive malware
start: Timestamp when the false positive was identified
categoryOutcome: /Success
categoryBehavior: /Modify/Content
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: /Informational
categoryTupleDescription: False Positive 6<externalid> mark_false_positive by mandiant
msg: False Positive <externalid> mark_false_positive by mandiant

User-initiated false positive

No CEF log is recorded when a user marks or unmarks a false positive condition. However, the following informational log message is recorded in the appliance logs instead:

False Positive action taken on malware alerts. Filter: <false-positive-filter-ID> is <marked False Positive | no longer a False Positive> by user <user>