Quarantine file user action log fields

Prev Next

When a user attempts to delete or restore a file from the malware quarantine area, CEF log messages are written.

CEF log entries are also written when the agent automatically attempts to perform malware remediation on a file in which malware has been detected. See Malware automatic remediation log fields . In addition, CEF log entries are written when a file ages out of the quarantine area. See Quarantine File Aging Log Fields

Deleting a quarantined file

When a user attempts to delete a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:

cs3Label: Quarantine Action
cs3: delete
request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/delete

Restoring a quarantined file

When a user attempts to restore a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:

cs3Label: Quarantine Action
cs3: restore
request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/restore

Common quarantine file user action fields

The following fields are common to all quarantine file user action CEF log entries.

Name: FireEye Quarantine Request
ID: FireEye Quarantine Request
cs4Label: Quarantine ID
cs4: The unique ID for the quarantine
cs5Label: Target GMT Offset 
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event or the SHA1 hash
act: Quarantine <host> request <Queued | Success | Failed>
msg: Host <host> quarantine request <Queued | Success | Failed>
externalId: Task ID used to track the requested task in the database
start: Timestamp for the start of the remediation attempt on the destination host
categoryOutcome: </Success | /Failure>
categoryBehavior: <Queued | Success | Failed | /Access/Start>
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: </Informational | /Informational/error>
categoryTupleDescription: <action> request.