CEF Extension Field Key=Value Pair Definitions

Prev Next

Trellix uses the following parameters in its CEF extension field key=value pairs:

CEF:0|<vendor>|<product name>|<version>|<cef event type>|<event-name>|<severity>|<extension>

The following table provides definitions for each extension field key in a CEF message.

Note

The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime

Ext. Field Key

Description

Products

Event Type

Data Type

Release

act=

deviceAction When act=blocked, the alert has been blocked.

When act=notified, the alert is not blocked.

CM

AX

EX

FX

NX

DM

IE

IM

MC

MO

RC

RO

WI

String 63 characters

7.5 and later

act=

alert action

  • Acquisition {Create|Status}

  • Containment {Approved|Requested}

  • Detection {Exd|IOC|MAL} Hit

  • Notified

  • Policy update

  • Quarantine <id> {QUARANTINED|RESTORED}

  • Stop Containment Approved

For example: act=Containment Requested

HX

AC

AS

CA

CC

CQ

CR

CS

EF

FP

IF

IM

MH

RI

SC

String

9.9.0

cat=

deviceEventCategory The originating device assigns the category. For example: cat=retro-detection

CM

AX

EX

FX

NX

MO

String 1023 characters

7.x

8.x

categoryBehavior=

For example: categoryBehavior=/Found

HX

AC

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

categoryDeviceGroup=

For example: categoryDeviceGroup=/IDS/Application/Service

HX

AC

AQ

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

categoryDeviceType=

For example: categoryDeviceType=Exploit Detection

HX

AC

AQ

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

categoryObject=

For example: categoryObject=/Host

HX

AC

AQ

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

categoryOutcome=

For example: categoryOutcome=/Success

HX

AC

AS

CA

CC

CQ

EF

FP

IF

MH

String

9.9.0

categorySignificance=

For example: categorySignificance=/Compromise

HX

AC

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

categoryTechnique=

For example: categoryTechnique=Exploit

HX

EF

IF

MH

String

9.9.0

categoryTupleDescription=

For example: categoryTupleDescription=A Host Acquisition was successfully queued.

HX

AC

AQ

AS

CA

CC

CQ

CR

CS

EF

FP

IF

MH

SC

String

9.9.0

cfp1=

deviceCusomFloatingPoint1 cfp1 represents the revision of the signature. For example: cfp1=10

CM

AX

EX

FX

NX

IE

Floating point

7.x

8.x

cfp1Label=

deviceCustomFloatingPoint1Label cfp1Label is the corresponding label field for cfp1. For example: cfp1Label=signature revision

CM

AX

EX

FX

NX

IE

String 1023 characters

7.x

8.x

cn1=

deviceCustomNumber1 cn1 represents the VLAN ID of the infected host. For example: cn1=0

CM

AX

EX

FX

NX

DM

IE

IM

MC MO RC

RI

RO

WI

Numeric Integer Long

7.x

8.x

cn1Label=

deviceCustom Number1Label cn1Label is the corresponding label field for cn1. For example: cn1Label=vlan

NX

AX

FX

EX

CM

DM

IE

IM

MC MO RC

RI

RO

WI

String 1023 characters

7.x

8.x

cn2=

deviceCustomNumber2 cn2 represents the signature ID. When there is duplicate malware, cn2 is the alert ID of the original malware. For example: cn2=83145120

AX

EX

FX

NX

CM

WI

MC

IM

DM MO

IE

RC

RO

Numeric Integer Long

7.x

8.x

cn2Label=

deviceCustomNumber2Label cn2Label is the corresponding label field for cn2. For example: cn2Label=sid

AX

EX

FX

NX

CM

DM

IE

IM

MC MO RC

RO

WI

String 1023 characters

7.x

8.x

cn3=

deviceCustomNumber3 cn3 represents the CnC listening server port. For example: cn3=53

AX

EX

FX

NX

CM

DM

IE

IM

MC MO RC

RO

WI

Numeric Integer Long

7.x

8.x

cn3Label=

deviceCustomNumber3Label cn3Label is the corresponding label field for cn3. For example: cn3Label=cncport

AX

EX

FX

NX

CM

DM

IE

IM

MC MO RC

RO

WI

String 1023 characters

7.x

8.x

cnt=

baseEventCount cnt represents how many times an event was observed. For example: cnt=1

NX

CM

IE

Integer

7.x

8.x

cs1=

deviceCustom string1 cs1 represents the malware signature name. On Endpoint Security servers, it represents the host agent certificate hash, For example: cs1=Trojan.PWS.OnlineGames Endpoint Security: cs1=uP1q4KNadwaber6XLK6BZU

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

FP

IE

IF

IM

MC MH MO RC

RI

RO

SC

WI

String 1023 characters

7.x

8.x

cs1Label=

deviceCustom string1Label cs1Label is the corresponding label field for cs1. For example: cs1Label=sname Endpoint Security: cs1Label=Host Agent Cert Hash

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

FP

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 1023 characters

7.x

8.x

cs2=

deviceCustomString2 cs2 represents attributes of OS changes made by the malware, data theft, or miscellaneous anomaly. On Endpoint Security servers, ir represents the Trellix Agent Version. For example: cs2=misc-anomaly, datatheft-anomaly Endpoint Security: cs2=29.7.0

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

FP

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 4000 characters

8.x

cs2Label=

deviceCustomString2Label cs2Label is the corresponding label field for cs2. For example: cs2Label=anomaly Endpoint Security: cs2Label=Trellix Agent Version

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

FP

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 1023 characters

7.x

8.x

9.9.0 (HX)

cs3=

deviceCustomString3 cs3 represents MVX OS information (name and version). On Endpoint Security servers, it represents a script. For example: cs3=Microsoft WindowsXP Professional 5.1 sp2; Microsoft Windows7 Professional 6.1 base; Microsoft WindowsXP Professional 5.1 base; Microsoft WindowsXP Professional 5.1 sp3 Endpoint Security: cs3=Timestamped Triage

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CC

CQ

CS

DM

IE

IM

MO RC

RI

RO

WI

String 4000 characters

7.x

8.x

9.9.0 (HX)

cs3Label=

deviceCustomString3Label cs3Label is the corresponding label field for cs3. For example: cs3Label=osinfo

AX

EX

FX

HX

NX

CM

AC

AS

CC

CQ

CS

DM

IE

IM

MC MO RC

RI

RO

WI

String 1023 characters

7.x

8.x

cs4=

deviceCustomString4 cs4 represents the alert URL. On Endpoint Security servers, it represents the process name. For example: cs4=https://xxx.xxx.xxx.xxx/event_stream /events_for_bot?ma_id\=51056&amp;lms_iden \=00:25:90:54:7E:6E cs1Label=sname cs1=Trojan.Generic Endpoint Security: cs4=chrome.exe

AX

EX

FX

HX

NX

CM

DM

EF

IE

IF

IM

MC MH MO RC

RI

RO

WI

String 4000 characters

7.x

8.x

cs4Label=

deviceCustomString4Label cs4Label is the corresponding label field for cs4. For example: cs4Label=link

AX

EX

FX

HX

NX

CM

DM

EF

IE

IF

IM

MC MH MO RC

RI

RO

WI

String 1023 characters

7.x

8.x

cs5=

deviceCustomString5 cs5 represents the hostname of the CnC server; if the appliance is unable to resolve the CnC server's hostname, this field will contain the IP address of the CnC server. On Endpoint Security servers, it represents the Target GMT Offset. For example: cs5=91.188.60.10 Endpoint Security: cs5=PT0H

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 4000 characters

7.x

8.x

cs5Label=

deviceCustomString5Label cs5Label is the corresponding label field for cs5. For example: cs5Label=cnchost Endpoint Security: cs5Label=Target GMT Offset

AX

FX

EX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 1023 characters

7.x

8.x

cs6=

deviceCustom string6 cs6 represents the CNC channel. Each line feedback is replaced with "::~~". On Endpoint Security servers, it represents the target OS. For example: (not applicable for release 6.0; same for releases 6.1 and later) cs6=GET /message.php?subid\=148&amp;version \=_nn2&amp;id\=XG0FZ7W00ZHZZHKZB0WY HTTP /1.1::~~Host: smartcontrol.info::~~User-Agent: firefox.exe;Windows NT 5.1::~~::~~ Endpoint Security: cs6=Windows 10 Enterprise 17763

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS

DM

EF

IE

IF

IM

MC MH MO RC

RO

SC

WI

String 4000 characters

7.x

8.x

cs6Label=

deviceCustom string6 Label cs6Label is the corresponding label field for cs6. For example: (not applicable for release 6.0; same for releases 6.1 and later) cs6Label=channel Endpoint Security: cs6Label=Target OS

AX

EX

FX

HX

NX

CM

AC

AQ

AS

CA

CC

CQ

CR

CS DM

EF

IE

IF

IM MC MH MO RC

RO

SC

WI

String 1023 characters

7.x

8.x

cs7=

For example: cs7=BLOCK

HX

EF

IF

MH

String

9.9.0

cs7label=

For example cs7Label=Resolution

HX

EF

IF

MH

String

9.9.0

cs8=

For example: cs8=xplt,blk

HX

EF

IF

MH

String

9.9.0

cs8Label=

For example: cs8Label=Alert Types

HX

EF

IF

MH

String

9.9.0

cs9=

MD5 hash For example: cs9=06f391ea3f127ffc3bba3d56f374077f

HX

MH

String

9.9.0

cs9Label=

cs9Label is the corresponding label field for cs9. For example: cs9Label=MD5

HX

MH

String

9.9.0

cs10=

SHA1 hash For example: cs10=2a85b25f583127a3903bbcd1c7187bcdb58b5c5b

HX

MH

String

9.9.0

cs10Label=

cs10Label is the corresponding label field for cs10. For example: cs10Label=SHA1

HX

MH

String

9.9.0

cs11=

Malware signature For example: cs11=Generic.mg.06f391ea3f127ffc

HX

MH

String

9.9.0

cs11Label=

cs11Label is the corresponding label field for cs11. For example: cs11Label=Malware Signature

HX

MH

String

9.9.0

cs12=

Malware category For example: cs12=file-event

HX

MH

String

9.9.0

cs12label=

cs121Label is the corresponding label field for cs12. For example: cs12Label=Malware Category

HX

MH

String

9.9.0

cs13=

For example: cs13=MG

HX

MH

String

9.9.0

cs13Label=

cs131Label is the corresponding label field for cs13. For example: cs13Label=Malware Engine

HX

MH

String

9.9.0

c6a1=

deviceCustomIPv6Address1 c6a1 represents the IPv6 address of the Trellix device. For example: c6a1=fe80::225:90ff:fe86:73d0

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RO

WI

IPv6 address

7.7 and later

c6a1Label=

deviceCustomIPv6Address1Label c6a1Label is the corresponding label field for c6a1. For example: c6a1Label=Device Address

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RO

WI

String 1023 characters

7.7 and later

c6a2=

deviceCustomIPv6Address2 c6a2 represents one of the IPv6 address fields. For example: c6a2=2011::1:4fdd:f5e2

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RO

WI

IPv6 address

7.7 and later

c6a2Label=

deviceCustomIPv6Address2Label c6a2Label is the corresponding label field for c6a2. For example: c6a2Label=Victim IP

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RO

WI

String

7.7 and later

c6a3=

deviceCustomIPv6Address3 c6a3 represents one of the IPv6 address fields. For example: c6a3=2011::1:7b2d:ffe7

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO

WI

IPv6 address

7.7 and later



Ext. Field Key

Description

Products

Event Type

Data Type

Release

c6a3Label=

deviceCustomIPv6Address3Label c6a3Label is the corresponding label field for c6a3. For example: c6a3Label=Attacker IP

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.7 and later

c6a4

deviceCustomIPv6Address4 c6a4 represents one of the IPv6 address fields. For example: c6a4=2011::1:7a2d:fbe7

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

IPv6 address

7.7 and later

c6a4label

deviceCustomIPv6Address4Label c6a4Label is the corresponding label field for c6a4. For example: c6a4Label=Attacker IP

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.7 and later

deviceCustomDate1=

For example: deviceCustomDate1=Feb 05 2019 17:01:52 UTC

HX

AC AQ AS

CA

CC CQ CR

CS

EF

IF

MH SC

Time Stamp mmddyyyy HH:mm:ss

9.9.0

deviceCustomDate1Label=

For example: deviceCustomDate1Label=Agent Last Audit

HX

AC AQ AS

CA

CC CQ CR

CS

EF

IF

MH SC

String

9.9.0

deviceCustomDate2=

For example: deviceCustomDate2=Feb 05 2019 17:00:22 UTC

HX

AC AQ AS

Time Stamp mmddyyyy HH:mm:ss

9.9.0

deviceCustomDate2Label=

For example: deviceCustomDate2Label=Triage Request Timestamp

HX

AC AQ AS

String

9.9.0

deviceExternalId=

The appliance ID, used for identifying alerts across multiple appliances. New appliances need to have the app processor, app search processor, and log service processes restarted after the appliance has been activated for the CEF logs to accurately display the appliance ID. If a new appliance is activated, and said processes are not restarted, the CEF logs will display the default appliance ID 870000000000. For example: deviceExternalId=8665C7396BD2

HX

PC

SU

String

4.9

devicePayloadId=

devicePayloadId represents the unique identifier for the payload associated with the event. For example: devicePayloadId=12bb338c-1482-48e2-b7b6-05afdcdfbece

AX

EX

FX

NX

CM

DM MC MO IM

RI

WI

String 128 characters

7.x

8.x

dhost=

destinationHostName For example: dhost=WIN11b1f2d1fea1

HX

AC AQ AS

CA

CC CQ CR

CS

EF

IF

MH SC

String

9.9.0

dmac=

destinationMacAddress dmac represents the MAC address. For example: dmac=00:50:56:e8:ba:21

AX

FX

EX

HX

NX

CM

AC AQ AS

CA

CC CQ CR

CS DM EF

IE

IF

IM MC MH MO RC

RI

RO SC

WI

MAC

Address

7.x

8.x

dntdom=

For example: dntdom=WORKGROUP

HX

AC AQ AS

CA

CC CQ CR

CS

EF

IF

MH SC

String

9.9.0

dproc=

destinationProcessName dproc represents the name of the target application running on the MVX during malware detection. For example: dproc=Firefox 4.0.0

AX

EX

FX

NX

CM

DM MC

IE

IM MO WI

String 1023 characters

7.x

8.x

dpt=

destinationPort dpt represents the port of the destination when any communication to an external host is observed. For example: dpt=20

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RI

RO WI

Integer

7.x

8.x

dst=

destinationAddress dst represents the IP address of the destination when any communication to an external host is observed. For example: dst=128.12.38.6

AX

EX

FX

HX

NX

CM

AC AQ AS

CA

CC CQ CR

CS DM EF

IE

IF

MC IM MH MO RC

RI

RO SC

WI

IPv4 Address 16 bytes

7.x

8.x

duser=

destinationUserName duser represents the recipient of the malicious email detected by a Trellix appliance. For example: duser=qa_test_1@mccoy.com

EX

CM

IE

MO

String 1023 characters

7.x

8.x

dvc=

deviceAddress dvc represents the device address of the Trellix appliance MVX. For example: dvc=xxx.xxx.xxx.xxx

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RI

RO WI

IPv4 address 16 bytes

7.x

8.x

dvchost=

deviceHostName dvchost represents the hostname or the fully qualified domain name of the device, if available. For example: dvchost=dave

AX

EX

FX

HX

NX

CM

AC AQ AS

CA

CC CQ CR

CS DM EF

FP

IE

IF

IM MC MH MO RC

RI

RO SC

WI

String 100 characters

7.x

8.x

end=

endTime end represents the time event-related activity ended.

EX

NX

RC

RI

RO

Time Stamp mmddyyyy hh:mm:ss

7.x

8.x

externalId=

externalId externalId represents the Trellix internal alert ID (which is external for ArcSight). For example: externalId=218799

AX

EX

FX

HX

NX

CM

AC AQ AS

CC CQ CS DM EF

FP

IE

IF

IM MC MH MO RC

RI

RO WI

Integer

7.x

8.x

fileHash=

fileHash fileHash represents the checksum of the malware object from a Trellix appliance MVX. For example: filehash=3174990d783f4a1bd5e99db60176b920

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 255 characters

7.x

8.x

filePath=

filePath filePath represents the local path (if the file is local) or the URL (if the file is remote) of the malware object. For example: filePath=test-infection.exe or filePath=xxx.xxx.xxx.xxx/qa-test-data/14R1-test-data/ mas-test-data/14R2-test-data/cve-samples/2014-1761.rtf

local to the detecting appliance: NX

AX

FX

EX

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.x

8.x

fileType=

fileType represents the file type of the detected malware. For example: fileType=jar

AX

EX

FX

NX

CM

MC MO

File extension, such as: exe pdf ppt doc docx...

7.x

8.x

flexString1=

flexString1 represents a sha256sum value. For example: flexString1=bb4f5c84c93528473539f9d8b8da4abaf08dbcaf64411a3 7c2f77594cc2f7ec1

NX

CM

IE

String

7.x

8.x

flexString1Label=

flexString1Label represents asha256sum label For example: flexString1Label=sha256sum

NX

CM

IE

String

7.x

8.x

flexString2=

String Number2 For NX, flexString2 represents the attack mode. For EX, flexString2 represents the SMTP email message subject line on the infected email. For example: flexString2=client flexString2Label=subject

NX

EX

CM

IE

String

For NX, the valid values are client, server, and N/A.

7.x

8.x

flexString2Label=

String Number2 Label flexString2Label is the corresponding label field for flexString2. For example: flexString2Label=attack mode

EX

NX

CM

IE

String

7.x

8.x

fname=

fname represents the name of file. For example: fname=apt.pdf

EX

FX

NX

CM

MO RO

string 1029 characters

7.x

8.x

fsize=

fsize represent the size of file. For example: fsize=177985

AX

EX

FX

NX

MO

Integer

8.x

headerFrom=

If enabled, headerFrom shows the sender email in header. To enable, use the fenotify preferences cef include-headeraddress enable CLI command. For example: headerFrom=test2@trellix.com

EX

CM

MO

String

8.x

headerTo=

If enabled, headerTo shows the recipient email in header. To enable, use the fenotify preferences cef include-headeraddress enable CLI command. For example: headerTo=ex-auto2@ebx-mailserver.com

EX

CM

MO

String

8.x

in=

For example: in=2154172

HX

AC

String

9.9.0

msg=

SMTPID msg represents the email message ID of the infected email. For IPS, msg represents the rule name. For example: msg=20121017232425.6706.77689.Email-48@Trellix .com msg=MVX Correlation

EX

HX

NX

CM

AC AQ AS

CA

CC CQ CR

CS

EF

FP

IE

IF

MH MO RI

SC

String 1023 characters

7.x 8.x 9.9.0 (HX)

outcome=

eventOutcome For example: outcome=Success

HX

PC

String 63 characters

2.5.0

proto=

transportProtocol proto represents the transport protocol detected by a Trellix appliance MVX. For example: proto=udp

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 31 characters

7.x

8.x

protoHeader=

Protocol Header protoHeader represents the protocol header. Each line feedback is replaced with "::~~". For example: protoHeader=GET /ba4ca624c2e5d01cfcf537891ec5c HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host: 16.16.16.11::~~Connection: Keep- Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 30 Sep 2015 16:02:39 GMT::~~Server: Apache/2.2.15 (CentOS)::~~Last-Modified: Tue, 29 Sep 2015 22:56:32 GMT::~~ETag: "1940779-ba988- 520eab99e6191"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type: text/plain; charset=UTF-8::~~

NX

CM

RC RO

String

8.x

reason=

For example: reason=update

HX

PC

String 1023 characters

2.5.0

request=

requestURL request represents the URL that needs to be investigated. For example: request=http://jrecsimpdegsa.ontheweb.nu/b/9/065a0b5a3b65 c1c6d5f5f8c883a9037237a6a6a28803d4e7a6876a26e2d00343

AX

EX

FX

HX

NX

CM

AC

CA CQ CR

CS DM

IE

IM MC MO RC

RI

RO SC

WI

String 1023 characters

7.x 8.x

requestClient-Application=

requestClientApplication requestClientApplication represents the user-agent for the request. For example: requestClientApplication=Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.0450

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.7 and later

requestContext=

requestContext requestContext represents where the request comes from. For example: requestContext=http://www.sb21980.cn/a10/fxx.htm

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 2048 characters

7.7 and later

requestMethod=

requestMethod requestMethod represents how a URL is accessed. For example, 'OPTIONS', 'POST', 'GET', 'HEAD', 'PUT', 'TRACE', 'CONNECT', or 'DELETE'. For example: requestMethod=GET

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.7 and later

rt=

deviceReceiptTime rt represents the malware event time as detected by a Trellix appliance MVX. For example: rt=Oct 17 2012 23:13:20 UTC

AX

EX

FX

HX

NX

CM

AC AQ AS

CA

CC CQ CR

CS DM EF

FP

IE IF IM MC MH MO MS RC RI RO SC WI

Time Stamp mmddyyyy hh:mm:ss

7.x 8.x

shost=

sourceHostName shost represents the hostname of the infected machine as detected by a Trellix appliance MVX. For example: shost=IM-testing.fe-notify-examples.com

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC RO WI

String 1023 characters

7.x 8.x

smac=

sourceMacAddress smac represents the source MAC address of the infected host. For example: smac=00:0c:29:76:bb:28

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RI

RO WI

MAC Address

7.x 8.x

sourceDnsDomain

sourceDnsDomain sourceDnsDomain represents the DNS domain portion of the FQDN. For example: sourceDnsDomain=Trellix .com

AX

EX

FX

NX

CM

MO RO

String 255 characters

7.x 8.x

sproc=

sourceProcessName sproc represents the source process name. For example: sproc=Java JDK JRE 7.13

AX

EX

FX

NX

CM

MC MO

String 1023 characte

7.x 8.x

spt=

sourcePort spt represents the infected host’s source port as detected by a Trellix appliance MVX. For example: spt=1116

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RI

RO WI

Integer Valid Port Numbers 0~65535

7.x 8.x

src=

sourceAddress src represents the IP address of the infected host. For example: src=192.168.85.141

AX

EX

FX

NX

CM

DM

IE

IM MC MO RC

RI

RO WI

IPv4 Address 16 bytes

7.x 8.x

start=

startTime Date when the event was originally analyzed by the appliance. For example: start=Nov 17 2016 10:30:38 UTC

EX

HX

EF

FP

IF

MH MO

Timestamp mmddyyyy hh:mm:ss UTC

7.x 8.x

suser=

SMTPSender suser represents the user name of the sender of the malicious email detected by a Trellix appliance. For example: suser=perfEmail@automation.local.vtttest.com

EX

HX

CM

AC

CA

CR

IE

MO SC

String 1023 characters

7.x 8.x