Triage and file acquisition log fields

Prev Next

When triages or file acquisitions are requested, CEF log messages are written.

Acquisition Queued

When a triage or file acquisition request is queued, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:

Name: FireEye Acquisition Queued
ID: FireEye Acquisition Queued
act: Acquisition Create
suser: User name requesting the acquisition

Acquisition Started

When a triage or file acquisition request is started, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:

Name: FireEye Acquisition Started
ID: FireEye Acquisition Started
act: Acquisition Status
suser: User name starting the acquisition

Acquisition Completed

When a triage or file acquisition request completes, CEF log messages include the following fields and field settings, in addition to the common CEF fields and the common triage and file acquisition fields:

Name: FireEye Acquisition Completed
ID: FireEye Acquisition Completed
act: Acquisition Status
suser: User name completing the acquisition
in: Size of resulting acquisition package (in bytes)
request: Direct URL of acquisition package

Common triage and file acquisition fields

The following fields are common to all triage and file acquisition CEF log entries.

categoryBehavior: /Create (for Created, Queued, Started), /Access/Start (for Completed)
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: /Informational
categoryTupleDescription: A description of the event
deviceCustomDate2Label: Triage Request Timestamp
deviceCustomDate2: The requested timestamp associated with the triage acquisition
cs3Label: Script Name
cs3: Name of acquisition script run on destination host: Triage, Timestamped Triage, API File Acquisition, Raw File Acquisition, Live Response Acquisition, Custom Acquisition, Bulk Acquisition, or Agent Diagnostic
cs4Label: Original Request ID
cs4: The event ID included with a triage request (by a SIEM user)
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
externalId: The HX unique ID for the acquisition request
fname: The requested filename for a file acquisition
filePath: The requested full path name for a file acquisition
msg: A text description of the event