Trellix uses the following parameters in its CEF extension field key=value pairs:
CEF:0|<vendor>|<product name>|<version>|<cef event type>|<event-name>|<severity>|<extension>
The following table provides definitions for each extension field key in a CEF message.
Note
The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime
Ext. Field Key | Description | Products | Event Type | Data Type | Release |
|---|---|---|---|---|---|
| deviceAction When act=blocked, the alert has been blocked. When act=notified, the alert is not blocked. | CM AX EX FX NX | DM IE IM MC MO RC RO WI | String 63 characters | 7.5 and later |
| alert action
For example: act=Containment Requested | HX | AC AS CA CC CQ CR CS EF FP IF IM MH RI SC | String | 9.9.0 |
| deviceEventCategory The originating device assigns the category. For example: cat=retro-detection | CM AX EX FX NX | MO | String 1023 characters | 7.x 8.x |
| For example: categoryBehavior=/Found | HX | AC AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| For example: categoryDeviceGroup=/IDS/Application/Service | HX | AC AQ AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| For example: categoryDeviceType=Exploit Detection | HX | AC AQ AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| For example: categoryObject=/Host | HX | AC AQ AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| For example: categoryOutcome=/Success | HX | AC AS CA CC CQ EF FP IF MH | String | 9.9.0 |
| For example: categorySignificance=/Compromise | HX | AC AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| For example: categoryTechnique=Exploit | HX | EF IF MH | String | 9.9.0 |
| For example: categoryTupleDescription=A Host Acquisition was successfully queued. | HX | AC AQ AS CA CC CQ CR CS EF FP IF MH SC | String | 9.9.0 |
| deviceCusomFloatingPoint1 cfp1 represents the revision of the signature. For example: cfp1=10 | CM AX EX FX NX | IE | Floating point | 7.x 8.x |
| deviceCustomFloatingPoint1Label cfp1Label is the corresponding label field for cfp1. For example: cfp1Label=signature revision | CM AX EX FX NX | IE | String 1023 characters | 7.x 8.x |
| deviceCustomNumber1 cn1 represents the VLAN ID of the infected host. For example: cn1=0 | CM AX EX FX NX | DM IE IM MC MO RC RI RO WI | Numeric Integer Long | 7.x 8.x |
| deviceCustom Number1Label cn1Label is the corresponding label field for cn1. For example: cn1Label=vlan | NX AX FX EX CM | DM IE IM MC MO RC RI RO WI | String 1023 characters | 7.x 8.x |
| deviceCustomNumber2 cn2 represents the signature ID. When there is duplicate malware, cn2 is the alert ID of the original malware. For example: cn2=83145120 | AX EX FX NX CM | WI MC IM DM MO IE RC RO | Numeric Integer Long | 7.x 8.x |
| deviceCustomNumber2Label cn2Label is the corresponding label field for cn2. For example: cn2Label=sid | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.x 8.x |
| deviceCustomNumber3 cn3 represents the CnC listening server port. For example: cn3=53 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | Numeric Integer Long | 7.x 8.x |
| deviceCustomNumber3Label cn3Label is the corresponding label field for cn3. For example: cn3Label=cncport | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.x 8.x |
| baseEventCount cnt represents how many times an event was observed. For example: cnt=1 | NX CM | IE | Integer | 7.x 8.x |
| deviceCustom string1 cs1 represents the malware signature name. On Endpoint Security servers, it represents the host agent certificate hash, For example: cs1=Trojan.PWS.OnlineGames Endpoint Security: cs1=uP1q4KNadwaber6XLK6BZU | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO RC RI RO SC WI | String 1023 characters | 7.x 8.x |
| deviceCustom string1Label cs1Label is the corresponding label field for cs1. For example: cs1Label=sname Endpoint Security: cs1Label=Host Agent Cert Hash | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO RC RO SC WI | String 1023 characters | 7.x 8.x |
| deviceCustomString2 cs2 represents attributes of OS changes made by the malware, data theft, or miscellaneous anomaly. On Endpoint Security servers, ir represents the Trellix Agent Version. For example: cs2=misc-anomaly, datatheft-anomaly Endpoint Security: cs2=29.7.0 | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO RC RO SC WI | String 4000 characters | 8.x |
| deviceCustomString2Label cs2Label is the corresponding label field for cs2. For example: cs2Label=anomaly Endpoint Security: cs2Label=Trellix Agent Version | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO RC RO SC WI | String 1023 characters | 7.x 8.x 9.9.0 (HX) |
| deviceCustomString3 cs3 represents MVX OS information (name and version). On Endpoint Security servers, it represents a script. For example: cs3=Microsoft WindowsXP Professional 5.1 sp2; Microsoft Windows7 Professional 6.1 base; Microsoft WindowsXP Professional 5.1 base; Microsoft WindowsXP Professional 5.1 sp3 Endpoint Security: cs3=Timestamped Triage | AX EX FX HX NX CM | AC AQ AS CC CQ CS DM IE IM MO RC RI RO WI | String 4000 characters | 7.x 8.x 9.9.0 (HX) |
| deviceCustomString3Label cs3Label is the corresponding label field for cs3. For example: cs3Label=osinfo | AX EX FX HX NX CM | AC AS CC CQ CS DM IE IM MC MO RC RI RO WI | String 1023 characters | 7.x 8.x |
| deviceCustomString4 cs4 represents the alert URL. On Endpoint Security servers, it represents the process name. For example: cs4=https://xxx.xxx.xxx.xxx/event_stream /events_for_bot?ma_id\=51056&lms_iden \=00:25:90:54:7E:6E cs1Label=sname cs1=Trojan.Generic Endpoint Security: cs4=chrome.exe | AX EX FX HX NX CM | DM EF IE IF IM MC MH MO RC RI RO WI | String 4000 characters | 7.x 8.x |
| deviceCustomString4Label cs4Label is the corresponding label field for cs4. For example: cs4Label=link | AX EX FX HX NX CM | DM EF IE IF IM MC MH MO RC RI RO WI | String 1023 characters | 7.x 8.x |
| deviceCustomString5 cs5 represents the hostname of the CnC server; if the appliance is unable to resolve the CnC server's hostname, this field will contain the IP address of the CnC server. On Endpoint Security servers, it represents the Target GMT Offset. For example: cs5=91.188.60.10 Endpoint Security: cs5=PT0H | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF IM MC MH MO RC RO SC WI | String 4000 characters | 7.x 8.x |
| deviceCustomString5Label cs5Label is the corresponding label field for cs5. For example: cs5Label=cnchost Endpoint Security: cs5Label=Target GMT Offset | AX FX EX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF IM MC MH MO RC RO SC WI | String 1023 characters | 7.x 8.x |
| deviceCustom string6 cs6 represents the CNC channel. Each line feedback is replaced with "::~~". On Endpoint Security servers, it represents the target OS. For example: (not applicable for release 6.0; same for releases 6.1 and later) cs6=GET /message.php?subid\=148&version \=_nn2&id\=XG0FZ7W00ZHZZHKZB0WY HTTP /1.1::~~Host: smartcontrol.info::~~User-Agent: firefox.exe;Windows NT 5.1::~~::~~ Endpoint Security: cs6=Windows 10 Enterprise 17763 | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF IM MC MH MO RC RO SC WI | String 4000 characters | 7.x 8.x |
| deviceCustom string6 Label cs6Label is the corresponding label field for cs6. For example: (not applicable for release 6.0; same for releases 6.1 and later) cs6Label=channel Endpoint Security: cs6Label=Target OS | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF IM MC MH MO RC RO SC WI | String 1023 characters | 7.x 8.x |
| For example: cs7=BLOCK | HX | EF IF MH | String | 9.9.0 |
| For example cs7Label=Resolution | HX | EF IF MH | String | 9.9.0 |
| For example: cs8=xplt,blk | HX | EF IF MH | String | 9.9.0 |
| For example: cs8Label=Alert Types | HX | EF IF MH | String | 9.9.0 |
| MD5 hash For example: cs9=06f391ea3f127ffc3bba3d56f374077f | HX | MH | String | 9.9.0 |
| cs9Label is the corresponding label field for cs9. For example: cs9Label=MD5 | HX | MH | String | 9.9.0 |
| SHA1 hash For example: cs10=2a85b25f583127a3903bbcd1c7187bcdb58b5c5b | HX | MH | String | 9.9.0 |
| cs10Label is the corresponding label field for cs10. For example: cs10Label=SHA1 | HX | MH | String | 9.9.0 |
| Malware signature For example: cs11=Generic.mg.06f391ea3f127ffc | HX | MH | String | 9.9.0 |
| cs11Label is the corresponding label field for cs11. For example: cs11Label=Malware Signature | HX | MH | String | 9.9.0 |
| Malware category For example: cs12=file-event | HX | MH | String | 9.9.0 |
| cs121Label is the corresponding label field for cs12. For example: cs12Label=Malware Category | HX | MH | String | 9.9.0 |
| For example: cs13=MG | HX | MH | String | 9.9.0 |
| cs131Label is the corresponding label field for cs13. For example: cs13Label=Malware Engine | HX | MH | String | 9.9.0 |
| deviceCustomIPv6Address1 c6a1 represents the IPv6 address of the Trellix device. For example: c6a1=fe80::225:90ff:fe86:73d0 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | IPv6 address | 7.7 and later |
| deviceCustomIPv6Address1Label c6a1Label is the corresponding label field for c6a1. For example: c6a1Label=Device Address | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.7 and later |
| deviceCustomIPv6Address2 c6a2 represents one of the IPv6 address fields. For example: c6a2=2011::1:4fdd:f5e2 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | IPv6 address | 7.7 and later |
| deviceCustomIPv6Address2Label c6a2Label is the corresponding label field for c6a2. For example: c6a2Label=Victim IP | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String | 7.7 and later |
| deviceCustomIPv6Address3 c6a3 represents one of the IPv6 address fields. For example: c6a3=2011::1:7b2d:ffe7 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | IPv6 address | 7.7 and later |
Ext. Field Key | Description | Products | Event Type | Data Type | Release |
|---|---|---|---|---|---|
| deviceCustomIPv6Address3Label c6a3Label is the corresponding label field for c6a3. For example: c6a3Label=Attacker IP | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.7 and later |
| deviceCustomIPv6Address4 c6a4 represents one of the IPv6 address fields. For example: c6a4=2011::1:7a2d:fbe7 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | IPv6 address | 7.7 and later |
| deviceCustomIPv6Address4Label c6a4Label is the corresponding label field for c6a4. For example: c6a4Label=Attacker IP | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.7 and later |
| For example: deviceCustomDate1=Feb 05 2019 17:01:52 UTC | HX | AC AQ AS CA CC CQ CR CS EF IF MH SC | Time Stamp mmddyyyy HH:mm:ss | 9.9.0 |
| For example: deviceCustomDate1Label=Agent Last Audit | HX | AC AQ AS CA CC CQ CR CS EF IF MH SC | String | 9.9.0 |
| For example: deviceCustomDate2=Feb 05 2019 17:00:22 UTC | HX | AC AQ AS | Time Stamp mmddyyyy HH:mm:ss | 9.9.0 |
| For example: deviceCustomDate2Label=Triage Request Timestamp | HX | AC AQ AS | String | 9.9.0 |
| The appliance ID, used for identifying alerts across multiple appliances. New appliances need to have the app processor, app search processor, and log service processes restarted after the appliance has been activated for the CEF logs to accurately display the appliance ID. If a new appliance is activated, and said processes are not restarted, the CEF logs will display the default appliance ID 870000000000. For example: deviceExternalId=8665C7396BD2 | HX | PC SU | String | 4.9 |
| devicePayloadId represents the unique identifier for the payload associated with the event. For example: devicePayloadId=12bb338c-1482-48e2-b7b6-05afdcdfbece | AX EX FX NX CM | DM MC MO IM RI WI | String 128 characters | 7.x 8.x |
| destinationHostName For example: dhost=WIN11b1f2d1fea1 | HX | AC AQ AS CA CC CQ CR CS EF IF MH SC | String | 9.9.0 |
| destinationMacAddress dmac represents the MAC address. For example: dmac=00:50:56:e8:ba:21 | AX FX EX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF IM MC MH MO RC RI RO SC WI | MAC Address | 7.x 8.x |
| For example: dntdom=WORKGROUP | HX | AC AQ AS CA CC CQ CR CS EF IF MH SC | String | 9.9.0 |
| destinationProcessName dproc represents the name of the target application running on the MVX during malware detection. For example: dproc=Firefox 4.0.0 | AX EX FX NX CM | DM MC IE IM MO WI | String 1023 characters | 7.x 8.x |
| destinationPort dpt represents the port of the destination when any communication to an external host is observed. For example: dpt=20 | AX EX FX NX CM | DM IE IM MC MO RC RI RO WI | Integer | 7.x 8.x |
| destinationAddress dst represents the IP address of the destination when any communication to an external host is observed. For example: dst=128.12.38.6 | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF IE IF MC IM MH MO RC RI RO SC WI | IPv4 Address 16 bytes | 7.x 8.x |
| destinationUserName duser represents the recipient of the malicious email detected by a Trellix appliance. For example: duser=qa_test_1@mccoy.com | EX CM | IE MO | String 1023 characters | 7.x 8.x |
| deviceAddress dvc represents the device address of the Trellix appliance MVX. For example: dvc=xxx.xxx.xxx.xxx | AX EX FX NX CM | DM IE IM MC MO RC RI RO WI | IPv4 address 16 bytes | 7.x 8.x |
| deviceHostName dvchost represents the hostname or the fully qualified domain name of the device, if available. For example: dvchost=dave | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO RC RI RO SC WI | String 100 characters | 7.x 8.x |
| endTime end represents the time event-related activity ended. | EX NX | RC RI RO | Time Stamp mmddyyyy hh:mm:ss | 7.x 8.x |
| externalId externalId represents the Trellix internal alert ID (which is external for ArcSight). For example: externalId=218799 | AX EX FX HX NX CM | AC AQ AS CC CQ CS DM EF FP IE IF IM MC MH MO RC RI RO WI | Integer | 7.x 8.x |
| fileHash fileHash represents the checksum of the malware object from a Trellix appliance MVX. For example: filehash=3174990d783f4a1bd5e99db60176b920 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 255 characters | 7.x 8.x |
| filePath filePath represents the local path (if the file is local) or the URL (if the file is remote) of the malware object. For example: filePath=test-infection.exe or filePath=xxx.xxx.xxx.xxx/qa-test-data/14R1-test-data/ mas-test-data/14R2-test-data/cve-samples/2014-1761.rtf | local to the detecting appliance: NX AX FX EX | DM IE IM MC MO RC RO WI | String 1023 characters | 7.x 8.x |
| fileType represents the file type of the detected malware. For example: fileType=jar | AX EX FX NX CM | MC MO | File extension, such as: exe pdf ppt doc docx... | 7.x 8.x |
| flexString1 represents a sha256sum value. For example: flexString1=bb4f5c84c93528473539f9d8b8da4abaf08dbcaf64411a3 7c2f77594cc2f7ec1 | NX CM | IE | String | 7.x 8.x |
| flexString1Label represents asha256sum label For example: flexString1Label=sha256sum | NX CM | IE | String | 7.x 8.x |
| String Number2 For NX, flexString2 represents the attack mode. For EX, flexString2 represents the SMTP email message subject line on the infected email. For example: flexString2=client flexString2Label=subject | NX EX CM | IE | String For NX, the valid values are client, server, and N/A. | 7.x 8.x |
| String Number2 Label flexString2Label is the corresponding label field for flexString2. For example: flexString2Label=attack mode | EX NX CM | IE | String | 7.x 8.x |
| fname represents the name of file. For example: fname=apt.pdf | EX FX NX CM | MO RO | string 1029 characters | 7.x 8.x |
| fsize represent the size of file. For example: fsize=177985 | AX EX FX NX | MO | Integer | 8.x |
| If enabled, headerFrom shows the sender email in header. To enable, use the fenotify preferences cef include-headeraddress enable CLI command. For example: headerFrom=test2@trellix.com | EX CM | MO | String | 8.x |
| If enabled, headerTo shows the recipient email in header. To enable, use the fenotify preferences cef include-headeraddress enable CLI command. For example: headerTo=ex-auto2@ebx-mailserver.com | EX CM | MO | String | 8.x |
| For example: in=2154172 | HX | AC | String | 9.9.0 |
| SMTPID msg represents the email message ID of the infected email. For IPS, msg represents the rule name. For example: msg=20121017232425.6706.77689.Email-48@Trellix .com msg=MVX Correlation | EX HX NX CM | AC AQ AS CA CC CQ CR CS EF FP IE IF MH MO RI SC | String 1023 characters | 7.x 8.x 9.9.0 (HX) |
| eventOutcome For example: outcome=Success | HX | PC | String 63 characters | 2.5.0 |
| transportProtocol proto represents the transport protocol detected by a Trellix appliance MVX. For example: proto=udp | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 31 characters | 7.x 8.x |
| Protocol Header protoHeader represents the protocol header. Each line feedback is replaced with "::~~". For example: protoHeader=GET /ba4ca624c2e5d01cfcf537891ec5c HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host: 16.16.16.11::~~Connection: Keep- Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 30 Sep 2015 16:02:39 GMT::~~Server: Apache/2.2.15 (CentOS)::~~Last-Modified: Tue, 29 Sep 2015 22:56:32 GMT::~~ETag: "1940779-ba988- 520eab99e6191"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type: text/plain; charset=UTF-8::~~ | NX CM | RC RO | String | 8.x |
| For example: reason=update | HX | PC | String 1023 characters | 2.5.0 |
| requestURL request represents the URL that needs to be investigated. For example: request=http://jrecsimpdegsa.ontheweb.nu/b/9/065a0b5a3b65 c1c6d5f5f8c883a9037237a6a6a28803d4e7a6876a26e2d00343 | AX EX FX HX NX CM | AC CA CQ CR CS DM IE IM MC MO RC RI RO SC WI | String 1023 characters | 7.x 8.x |
| requestClientApplication requestClientApplication represents the user-agent for the request. For example: requestClientApplication=Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.0450 | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.7 and later |
| requestContext requestContext represents where the request comes from. For example: requestContext=http://www.sb21980.cn/a10/fxx.htm | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 2048 characters | 7.7 and later |
| requestMethod requestMethod represents how a URL is accessed. For example, 'OPTIONS', 'POST', 'GET', 'HEAD', 'PUT', 'TRACE', 'CONNECT', or 'DELETE'. For example: requestMethod=GET | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.7 and later |
| deviceReceiptTime rt represents the malware event time as detected by a Trellix appliance MVX. For example: rt=Oct 17 2012 23:13:20 UTC | AX EX FX HX NX CM | AC AQ AS CA CC CQ CR CS DM EF FP IE IF IM MC MH MO MS RC RI RO SC WI | Time Stamp mmddyyyy hh:mm:ss | 7.x 8.x |
| sourceHostName shost represents the hostname of the infected machine as detected by a Trellix appliance MVX. For example: shost=IM-testing.fe-notify-examples.com | AX EX FX NX CM | DM IE IM MC MO RC RO WI | String 1023 characters | 7.x 8.x |
| sourceMacAddress smac represents the source MAC address of the infected host. For example: smac=00:0c:29:76:bb:28 | AX EX FX NX CM | DM IE IM MC MO RC RI RO WI | MAC Address | 7.x 8.x |
| sourceDnsDomain sourceDnsDomain represents the DNS domain portion of the FQDN. For example: sourceDnsDomain=Trellix .com | AX EX FX NX CM | MO RO | String 255 characters | 7.x 8.x |
| sourceProcessName sproc represents the source process name. For example: sproc=Java JDK JRE 7.13 | AX EX FX NX CM | MC MO | String 1023 characte | 7.x 8.x |
| sourcePort spt represents the infected host’s source port as detected by a Trellix appliance MVX. For example: spt=1116 | AX EX FX NX CM | DM IE IM MC MO RC RI RO WI | Integer Valid Port Numbers 0~65535 | 7.x 8.x |
| sourceAddress src represents the IP address of the infected host. For example: src=192.168.85.141 | AX EX FX NX CM | DM IE IM MC MO RC RI RO WI | IPv4 Address 16 bytes | 7.x 8.x |
| startTime Date when the event was originally analyzed by the appliance. For example: start=Nov 17 2016 10:30:38 UTC | EX HX | EF FP IF MH MO | Timestamp mmddyyyy hh:mm:ss UTC | 7.x 8.x |
| SMTPSender suser represents the user name of the sender of the malicious email detected by a Trellix appliance. For example: suser=perfEmail@automation.local.vtttest.com | EX HX CM | AC CA CR IE MO SC | String 1023 characters | 7.x 8.x |