The Endpoint Security (HX) logs messages when a malware scan is run on an endpoint host. In addition to the common CEF fields, malware scan logging includes the following fields and field settings:
Malware Scan
Name: Malware Scan ID: Malware Scan cs2Label: Scan Type cs2: The type of malware scan (full, quick, or memory) cs3Label: Scan Time Taken in Seconds cs3: The scan time, in seconds cs4Label: Infected Objects Count cs4: The number of infected objects found during the scan cs5Label: Actioned Objects Count cs5: The number of objects for which action is taken cs6Label: Scanned Objects Count cs6: The number of objects scanned cs7Label: Alert Correlation ID cs7: The hash of the alert ID act: Malware Scan msg: Host <host> Malware Scan externalId: start: Timestamp when the malware scan was started on the host endpoint categoryOutcome: /Success categoryBehavior: /Scan categoryDeviceGroup: /IDS categoryDeviceType: Malware Protection categoryTechnique: Malware categoryObject: /Host categorySignificance: /Scan categoryTupleDescription: Malware Scan was performed on host.