Malware scan log fields

Prev Next

The Endpoint Security (HX) logs messages when a malware scan is run on an endpoint host. In addition to the common CEF fields, malware scan logging includes the following fields and field settings:

Malware Scan

Name: Malware Scan
ID: Malware Scan
cs2Label: Scan Type
cs2: The type of malware scan (full, quick, or memory)
cs3Label: Scan Time Taken in Seconds
cs3: The scan time, in seconds
cs4Label: Infected Objects Count
cs4: The number of infected objects found during the scan
cs5Label: Actioned Objects Count
cs5: The number of objects for which action is taken
cs6Label: Scanned Objects Count
cs6: The number of objects scanned
cs7Label: Alert Correlation ID
cs7: The hash of the alert ID
act: Malware Scan
msg: Host <host> Malware Scan
externalId: 
start: Timestamp when the malware scan was started on the host endpoint
categoryOutcome: /Success
categoryBehavior: /Scan
categoryDeviceGroup: /IDS
categoryDeviceType: Malware Protection
categoryTechnique: Malware
categoryObject: /Host
categorySignificance: /Scan
categoryTupleDescription: Malware Scan was performed on host.