When triages or file acquisitions are requested, CEF log messages are written.
Acquisition Queued
When a triage or file acquisition request is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:
Name: FireEye Acquisition Queued ID: FireEye Acquisition Queued act: Acquisition Create suser: User name requesting the acquisition
Acquisition Started
When a triage or file acquisition request is started, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:
Name: FireEye Acquisition Started ID: FireEye Acquisition Started act: Acquisition Status suser: User name starting the acquisition
Acquisition Completed
When a triage or file acquisition request completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:
Name: FireEye Acquisition Completed ID: FireEye Acquisition Completed act: Acquisition Status suser: User name completing the acquisition in: Size of resulting acquisition package (in bytes) request: Direct URL of acquisition package
Common triage and file acquisition fields
The following fields are common to all triage and file acquisition CEF log entries.
categoryBehavior: /Create (for Created, Queued, Started), /Access/Start (for Completed) categoryDeviceGroup: /IDS/Application/Service categoryDeviceType: Forensic Investigation categoryObject: /Host categorySignificance: /Informational categoryTupleDescription: A description of the event deviceCustomDate2Label: Triage Request Timestamp deviceCustomDate2: The requested timestamp associated with the triage acquisition cs3Label: Script Name cs3: Name of acquisition script run on destination host: Triage, Timestamped Triage, API File Acquisition, Raw File Acquisition, Live Response Acquisition, Custom Acquisition, Bulk Acquisition, or Agent Diagnostic cs4Label: Original Request ID cs4: The event ID included with a triage request (by a SIEM user) cs5Label: Target GMT Offset cs5: The GMT offset of the host generating the event in ISO 8601 duration format cs6Label: Target OS cs6: The operating system of the host generating the event externalId: The HX unique ID for the acquisition request fname: The requested filename for a file acquisition filePath: The requested full path name for a file acquisition msg: A text description of the event