False Positive Updated (Endpoint Security)
- Published on Aug 25, 2026
Prev Next CEF:0|trellix|hx|2.5.0|Trellix False Positive Updated|Trellix False Positive Updated|0|rt=Oct 30 2017 18:16:55
UTC dvchost=<HX host name> categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic
Investigation categoryObject=/Host externalId=6329be27f0f6cc1f1bee161f369921d9 start=Oct 30 2017 18:16:55 UTC
categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Modify/Content act=False Positive
msg=False Positive external ID> mark_false_positive by mandiant categoryTupleDescription=False Positive
6329be27f0f6cc1f1bee161f369921d9 mark_false_positive by mandiant cs1Label=False Positive action
cs1=mark_false_positive cs2Label=condition cs2=<condition marked false positive>
Was this article helpful?
Related articles
Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type
Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type
Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type
Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type