When a user attempts to delete or restore a file from the malware quarantine area, CEF log messages are written.
CEF log entries are also written when the agent automatically attempts to perform malware remediation on a file in which malware has been detected. See Malware automatic remediation log fields . In addition, CEF log entries are written when a file ages out of the quarantine area. See Quarantine File Aging Log Fields
Deleting a quarantined file
When a user attempts to delete a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:
cs3Label: Quarantine Action cs3: delete request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/delete
Restoring a quarantined file
When a user attempts to restore a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:
cs3Label: Quarantine Action cs3: restore request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/restore
Common quarantine file user action fields
The following fields are common to all quarantine file user action CEF log entries.
Name: FireEye Quarantine Request ID: FireEye Quarantine Request cs4Label: Quarantine ID cs4: The unique ID for the quarantine cs5Label: Target GMT Offset cs5: The GMT offset of the host generating the event in ISO 8601 duration format cs6Label: Target OS cs6: The operating system of the host generating the event or the SHA1 hash act: Quarantine <host> request <Queued | Success | Failed> msg: Host <host> quarantine request <Queued | Success | Failed> externalId: Task ID used to track the requested task in the database start: Timestamp for the start of the remediation attempt on the destination host categoryOutcome: </Success | /Failure> categoryBehavior: <Queued | Success | Failed | /Access/Start> categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: </Informational | /Informational/error> categoryTupleDescription: <action> request.