Security content updates log fields

Prev Next

The Endpoint Security (HX) logs a message each time a new security content update is downloaded from DTI to the Endpoint Security (HX). In addition to the common CEF fields, logs for security content updates include the following fields and field settings:

Security content updates

Time: Timestamp of log entry 
Name: FireEye Security Content Updated
ID: FireEye Security Content Updated
cs4Label: Security Content Version
cs4: The Security Content version the server is running
cs5Label: Security Content Last Applied
cs5: The timestamp of when the newest Security Content was applied
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host 
categoryOutcome: /Success
categorySignificance: /Informational 
categoryBehavior: /Modify/Content
categoryTupleDescription: Security Content version <version> applied at <timestamp> 
act: Security Content Status
msg: Security Content version <version> applied at <timestamp>