When a file ages out of the quarantine area (when it exceeds the quarantine area retention period), malware logging includes the following fields and field settings, in addition to the common CEF fields:
CEF log entries are also written when the agent automatically attempts to perform malware remediation on a file in which malware has been detected. See Malware automatic remediation log fields . In addition, CEF log entries are written when a user attempts to delete or restore a file in which malware has been detected. See Quarantine file user action log fields .
Name: FireEye Quarantine Completed ID: FireEye Quarantine Completed cs3Label: Quarantine Action cs3: <purge | restore |restore_failed> cs4Label: Quarantine ID cs4: The unique ID for the quarantine cs5Label: Correlation ID cs5: The correlation ID. cs6Label: SHA1 cs6: The SHA1 hash act: Quarantine <host> <aged out | restored | restore failed> msg: Host <host> quarantine action filePath: The fully qualified file path of the quarantined and cleaned file fileHash: The file hash of the quarantined file name fsize: The size of the quarantined file start: Timestamp for the start of the quarantine file removal categoryOutcome: /Success categoryBehavior: /Access/Start categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: /Informational categoryTupleDescription: One of the following: <Quarantine task successfully completed, file cleaned | Quarantine task successfully completed, file deleted|Quarantine task failed to complete.>.