The following table describes the fields included in the daily digest notifications for all protocols.
Field | Description |
|---|---|
alertType | Type of alert. |
alertid | Trellix internal alert ID (which is external for ArcSight). |
product | Name of Trellix product. |
release | Trellix software release. |
fileHash | Checksum of the malware object from a Trellix appliance MVX engine. |
dvchost | Hostname of a Trellix appliance performing the detection and sending the notification. |
sname | Trellix-assigned signature name. |
dvc | Device address of the detecting Trellix appliance MVX engine. |
locations | Geographical location of the botnet C&C server, if known. |
malware_type | Type of malware. |
sev | Severity level of the event. Range: 0 through 10. The highest event severity level is 10. |
occurred | Time that the malware event occurred as detected by a Trellix appliance MVX engine. |
mwurl | URL that triggered the malware event. |
link | URL of the infection or alert that is local to the detecting appliance. |
src | IP address of the infected host. |
action | Type of action (notified or blocked) that was taken by the Trellix appliance MVX engine. |
objurl | Detailed information about the detected malware URL. |
sid | Trellix internal alert signature ID that is assigned for malware detection. |
stype | Trellix-assigned signature type that is used for malware detection. |
profile | Guest image profile and version that is used for malware detection. |
malware-note | Notes about the malware. |
application | Name of the target application that is running on the MVX engine during malware detection. |
original_name | Original file name of the malware. |
header | Protocol header. |
anomaly | Attributes of operating system (OS) changes made by the malware, data theft, or miscellaneous anomaly. |
osinfo | Information about the OS name and version. |
cnchost | Hostname of the command and control (CnC) server, if known. This field will display the IP address if the appliance cannot determine the hostname. |
channel | CnC channel. |
cncport | Port number of the CnC listening server. |
os | Application name of the target OS. |
app | Name of the target application that is running on the MVX engine during malware detection. |
shost | Hostname of the infected machine as detected by aTrellix appliance MVX engine, if available. |
spt | Source port number of the infected host as detected by a Trellix appliance MVX engine. |
smac | Source MAC address of the infected host. |
dst | IP address of the destination when any communication to an external host is observed within the MVX engine. |
dmac | MAC address of the destination when any communication to an external host is observed within the MVX engine. |
dpt | Port number of the destination when any communication to an external host is observed within the MVX engine. |