The Endpoint Security (HX) logs messages when malware is marked as false positive and when it is changed back to true positive. In addition to the common CEF fields, malware false positive logging includes the following fields and field settings.
DTI-marked false positive:
Name: FireEye False Positive Updated ID: FireEye False Positive Updated cs1Label: False Positive action (differs from the common CEF fields) cs1: mark_false_positive (differs from the common CEF fields) cs2Label: condition (differs from the common CEF fields) cs2: <condition that was marked false positive> (differs from the common CEF fields) act: False Positive externalId: The HX unique identifier associated with the false positive malware start: Timestamp when the false positive was identified categoryOutcome: /Success categoryBehavior: /Modify/Content categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: /Informational categoryTupleDescription: False Positive 6<externalid> mark_false_positive by mandiant msg: False Positive <externalid> mark_false_positive by mandiant
User-initiated false positive
No CEF log is recorded when a user marks or unmarks a false positive condition. However, the following informational log message is recorded in the appliance logs instead:
False Positive action taken on malware alerts. Filter: <false-positive-filter-ID> is <marked False Positive | no longer a False Positive> by user <user>