Acquisition Queued (Endpoint Security)

Prev Next
CEF:0|Trellix|hx|9.9.0|Trellix Acquisition Queued|Trellix Acquisition
Queued|0|rt=Feb 05 2019 17:01:58 UTC dvchost=trellix-01cb28
categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic
Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash
cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25
dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last
Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent
Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS
cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name
cs3=Timestamped Triage deviceCustomDate2Label=Triage Request Timestamp
deviceCustomDate2=Feb 05 2019 17:00:22 UTC suser=automatic
categoryOutcome=/Success categorySignificance=/Informational
categoryBehavior=/Create act=Acquisition Create msg=Host WIN11b1f2d1fea1
Timestamped Triage queued by automatic categoryTupleDescription=A Host
Acquisition was successfully queued.