Quarantine file user action (Endpoint Security)

Prev Next
CEF:0|trellix|hx|2.5.0|Trellix Quarantine <Completed|Request>|Trellix Quarantine <Completed|Request>|0|rt=Oct 31
2017 10:29:14 UTC dvchost=<HX host name> categoryDeviceGroup=/IDS/Application/Service
categoryDeviceType=Forensic Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=<agent host
name hash> externalId=undefined start=Aug 18 2017 15:59:39 UTC categoryOutcome=/Success categorySignificance=/
Informational categoryBehavior=</Queued|/Access/Start> act=Quarantine <host name> <delete|restore> request
<failed|queued|success> msg=Host <host name> <delete|restore> quarantine request <failed|queued|success>
categoryTupleDescription=Quarantine <delete|restore> requests filePath=<path to quarantined file> fileHash=<hash
of quarantined file> fsize=<quarantined file size in bytes> cs3Label=Quarantine action cs3=<delete|restore>
cs4Label=Quarantine ID cs4=<quarantine unique ID> request=<request ID>