Quarantine file aging log fields

Prev Next

When a file ages out of the quarantine area (when it exceeds the quarantine area retention period), malware logging includes the following fields and field settings, in addition to the common CEF fields:

CEF log entries are also written when the agent automatically attempts to perform malware remediation on a file in which malware has been detected. See Malware automatic remediation log fields . In addition, CEF log entries are written when a user attempts to delete or restore a file in which malware has been detected. See Quarantine file user action log fields .

Name: FireEye Quarantine Completed

ID: FireEye Quarantine Completed

cs3Label: Quarantine Action

cs3: <purge | restore |restore_failed>

cs4Label: Quarantine ID

cs4: The unique ID for the quarantine

cs5Label: Correlation ID

cs5: The correlation ID.

cs6Label: SHA1

cs6: The SHA1 hash 

act: Quarantine <host> <aged out | restored | restore failed>

msg: Host <host> quarantine action

filePath: The fully qualified file path of the quarantined and cleaned file

fileHash: The file hash of the quarantined file name

fsize: The size of the quarantined file

start: Timestamp for the start of the quarantine file removal

categoryOutcome: /Success

categoryBehavior: /Access/Start

categoryDeviceGroup: /IDS/Application/Service

categoryDeviceType: Forensic Investigation

categoryObject: /Host

categorySignificance: /Informational

categoryTupleDescription: One of the following: <Quarantine task successfully completed, file cleaned | Quarantine task successfully completed, file deleted|Quarantine task failed to complete.>.