Note
If the field value is not present, that field is not part of the CEF notification.
The following table describes the CEF fields and values used for Email Security - Cloud Edition notifications.
Field | Value | Type | Mandatory | Variable | Length | Notes |
|---|---|---|---|---|---|---|
CEF | CEF | String | Yes | No | — | — |
Version | 0 | Int | Yes | No | — | — |
Device Vendor | Trellix | String | Yes | No | — | — |
Device Product | Email Security - Cloud | String | Yes | No | — | — |
Device Version | 3.0 | String | Yes | No | — | This string might increment in subsequent releases. |
Device Event Class ID | etp | String | Yes | No | — | — |
Name | malicious email/ace | String | Yes | Yes | — | — |
Severity | Value is between 1 and 10. | Number | Yes | No | — | — |
rt | Date in the following format: MMM dd yyyy HH:mm:ss UTC | Date | Yes | Yes | — | Timestamp at which the alert was generated in UTC. |
suser | Sender email address | String | Yes | Yes | 1023 characters | — |
duser | Destination email address | String | Yes | Yes | 1023 characters | — |
request | Malicious URL | String | No | Yes | 1023 characters | — |
fname | Malware file name | String | No | Yes | 1023 characters | — |
fileHash | Hash value of the file/URL | String | Yes | Yes | 255 characters | The format is MD5. |
destinationDnsDomain | Destination email address domain | String | Yes | Yes | 255 characters | — |
externalId | Database alert ID | String | Yes | Yes | 255 characters | — |
cs1Label | sname | String | Yes | No | 1023 characters | — |
cs1 | Trellix malware name | String | Yes | Yes | 400 characters | — |
cs3Label | Subject | String | Yes | No | 1023 characters | — |
cs3 | Message subject | String | Yes | Yes | 4000 characters | — |
cs4Label | Link | String | Yes | No | 1023 characters | — |
cs4 | URL to the alert page on the Email Security - Cloud portal | String | Yes | Yes | 4000 characters | — |
cs5Label | Client | String | Yes | No | 1023 characters | — |
cs5 | Customer ID | String | Yes | Yes | 4000 characters | — |
cs6Label | Trellix Advanced Threat Intelligence name, type, and level | String | No | No | 1023 characters | — |
cs6 | Data extracted from the Trellix Advanced Threat Intelligence service | String | No | Yes | 4000 characters | — |
flexString1Label | Trellix Advanced Threat Intelligence threat attribution | String | No | No | 128 characters | — |
flexString1 | Data extracted from the Trellix Advanced Threat Intelligence service | String | No | Yes | 1023 characters | — |