Trellix uses the following parameters in its CSV extension field key=value pairs:
Trellix:<product name>:<event-type>:<event-name>:<severity>:<extension>
The following table provides definitions for each extension field key in a CSV message.
Note
The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime
Ext. Field Key | Description | Products | Event Type | Data Type | Release |
|---|---|---|---|---|---|
fileHash= | fileHash
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 255 characters | 7.x 8.x |
src= | Source Address
For example:
| NX AX FX EX CM | WI MC IM DM MO | IPv4 Address 16 bytes | 7.x 8.x |
shost= | source hostname
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
proto= | Transport Protocol proto represents the transport protocol detected by a Trellix appliance MVX. 0 indicates no protocol detected. For example:
| NX AX FX EX CM | WI MC IM DM MO | String 31 characters | 7.x 8.x |
dvchost= | device hostname
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 100 characters | 7.x 8.x |
spt= | source port
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer Valid Port Numbers 0~65535 | 7.x 8.x |
dvc= | device Address
For example:
| NX AX FX EX CM | WI MC IM DM MO | IPv4 address 16 bytes | 7.x 8.x |
smtp-mail-from= | smtp-mail-from
For example:
| EX CM | MO | String 1023 characters | 7.x 8.x |
message-id= | message
For example:
| EX CM | MO | String 1023 characters | 7.x 8.x |
smac= | sourceMacAddress
For example:
| NX AX FX EX CM | WI MC IM DM MO | MAC Address | 7.x 8.x |
dmac= | destinationMacAddress
For example:
| NX AX FX EX CM | WI MC IM DM MO | MAC Address | 7.x 8.x |
alertid= | alertid
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer | 7.x 8.x |
smtp-to= | smtp-to
For example: smtp-to=x@y.com | EX CM | MO | String 1023 characters | 7.x 8.x |
app= | app
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
dst= | destinationName
For example:
| NX AX FX EX CM | WI MC IM DM MO | IPv4 Address 16 bytes | 7.x 8.x |
dpt= | destinationPort
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer | 7.x 8.x |
eventURL= | link
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
repository= |
For example:
| AX FX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
locations= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
application= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
vlan= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer | 7.x 8.x |
cnchost= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | IP address or String 1023 characters | 7.x 8.x |
cncport= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer | 7.x 8.x |
smtp-cc= |
For example:
| EX CM | MO | String 1023 characters | 7.x 8.x |
channel= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
header= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
action= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
osinfo= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
profile= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
sType= |
Available values: 'unknown', 'generated-content', 'trellix-content', 'bot-command', 'fqc', 'known-md5sum', duplicate-md5sum', 'av-match', 'MVX-bot-command', blacklist', 'yara', 'avs', 'archive', 'encoding', 'timestamp' For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
occurred= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | Time Stamp mmmddyyyy HH:mm:ss or millisecs since epoch | 7.x 8.x |
os= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
anomaly= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
sName= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | String 1023 characters | 7.x 8.x |
sID= |
For example:
| NX AX FX EX CM | WI MC IM DM MO | Integer | 7.x 8.x |
sev= | Severity For example:
| NX AX FX EX CM | WI MC IM DM MO IE RC RO | String representing minor, major, or critical severity. | 7.5 and later |
malware_type= | Type of malware For example:
| NX AX FX EX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
alertType= | Type of alert For example:
| NX AX FX EX CM | MC WI IM MO IE RC RO | String The valid values are domain-match, ips-event, infection-match, malware-callback, malware object, riskware-callback, riskware-object, and web-infection. | 7.x 8.x |
malware-note= | Notes about the malware | NX AX FX EX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
objurl= | The | NX AX FX EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
mwurl= | URL that triggered the malware event. For example:
| NX AX FX EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
product= | Product name For example:
| NX AX FX EX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
release= | Product release For example:
| NX AX FX EX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
link= | Link link represents the local path or URL of the malware object (local to the detecting appliance). For example:
| NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
original_name= | Original file name of the malware For example:
| NX AX FX EX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
protocol= | protocol represents the transport protocol detected by the Trellix appliance MVX. For example:
| EX CM | MC WI IM DM MO IE RC RO | Integer Valid values are 8 (URL), 9 (attachment), and 10 (header). | 7.x 8.x |
subject= | subject represents the SMTP email message subject line on the infected email. For example:
| EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
date= | Date when the alert was found. For example:
| EX CM | MC WI IM DM MO IE RC RO | Time stamp in the following format: yyyy-mm-ddTHH:mm | 7.x 8.x |
run_end= | End of process. For example:
| EX CM | MC WI IM DM MO IE RC RO | String 1023 characters Standard XML daytime format | 6.x 7.x 8.x |
last-malware= | last-malware represents the name associated with last malicious email infection. For example:
| EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
smtp-header= |
For example:
| EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
download_end= | End of download | EX CM | MC WI IM DM MO IE RC RO | Time stamp | 7.x 8.x |
sigId= | Trellix internal signature ID. For example:
| NX CM | MC WI IM DM MO IE RC RO | Integer | 7.x 8.x |
sigrevision= | Revision of the Trellix internal signature ID. For example:
| NX CM | MC WI IM DM MO IE RC RO | Integer | 7.x 8.x |
matchcount= | Number of matches For example
| NX CM | MC WI IM DM MO IE RC RO | Integer | 7.x 8.x |
signame= | Name of the Trellix internal signature ID. For example:
| NX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
cve_id= | CVE ID For example:
| NX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
action_taken= | Type of action taken For example:
| NX CM | MC WI IM DM MO IE RC RO | String Valid values are notified and blocked. | 7.x 8.x |
attack_mode= | Attack mode For example:
| NX CM | MC WI IM DM MO IE RC RO | String | 7.x 8.x |
mvx_status= | MVX status For example:
| NX CM | IE | String | 7.x 8.x |