The Endpoint Security (HX) logs a message each time a new security content update is downloaded from DTI to the Endpoint Security (HX). In addition to the common CEF fields, logs for security content updates include the following fields and field settings:
Security content updates
Time: Timestamp of log entry Name: FireEye Security Content Updated ID: FireEye Security Content Updated cs4Label: Security Content Version cs4: The Security Content version the server is running cs5Label: Security Content Last Applied cs5: The timestamp of when the newest Security Content was applied categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categoryOutcome: /Success categorySignificance: /Informational categoryBehavior: /Modify/Content categoryTupleDescription: Security Content version <version> applied at <timestamp> act: Security Content Status msg: Security Content version <version> applied at <timestamp>