CSV fields for daily digest notifications

Prev Next

The following table describes the fields included in the daily digest notifications for all protocols.

Field

Description

alertType

Type of alert.

alertid

Trellix internal alert ID (which is external for ArcSight).

product

Name of Trellix product.

release

Trellix software release.

fileHash

Checksum of the malware object from a managed Trellix appliance MVX engine.

dvchost

Hostname of a Trellix appliance performing the detection and sending the notification.

sname

Trellix-assigned signature name.

dvc

Device address of the detecting Trellix appliance MVX engine.

locations

Geographical location of the botnet CnC server, if known.

malware_type

Type of malware.

sev

Severity level of the event. Range: 0 through 10. The highest event severity level is 10.

occurred

Time that the malware event occurred as detected by a managed Trellix appliance MVX engine.

mwurl

URL that triggered the malware event.

link

URL of the infection or alert that is local to the detecting appliance.

src

IP address of the infected host.

action

Type of action (notified or blocked) that was taken by the managed Trellix appliance MVX engine.

objurl

Detailed information about the detected malware URL.

sid

Trellix internal alert signature ID that is assigned for malware detection.

stype

Trellix-assigned signature type that is used for malware detection.

profile

Guest image profile and version that is used for malware detection.

malware-note

Notes about the malware.

application

Name of the target application that is running on the MVX engine during malware detection.

original_name

Original file name of the malware.

header

Protocol header.

anomaly

Attributes of operating system (OS) changes made by the malware, data theft, or miscellaneous anomaly.

osinfo

Information about the OS name and version.

cnchost

Hostname of the command and control (CnC) server, if known. This field will display the IP address if the managed appliance cannot determine the hostname.

channel

CnC channel.

cncport

Port number of the CnC listening server.

os

Application name of the target OS.

app

Name of the target application that is running on the MVX engine during malware detection.

shost

Hostname of the infected machine as detected by a managed Trellix appliance MVX engine, if available.

spt

Source port number of the infected host as detected by a managed Trellix appliance MVX engine.

smac

Source MAC address of the infected host.

dst

IP address of the destination when any communication to an external host is observed within the MVX engine.

dmac

MAC address of the destination when any communication to an external host is observed within the MVX engine.

dpt

Port number of the destination when any communication to an external host is observed within the MVX engine.