| 
 CEF Key  | 
 Description  | 
 Value  | 
|---|---|---|
| 
 Header (logVer)  | 
 CEF format version  | 
 CEF:0  | 
| 
 Header (vendor)  | 
 Appliance vendor  | 
 Trend Micro  | 
| 
 Header (pname)  | 
 Appliance product  | 
 Apex Central  | 
| 
 Header (pver)  | 
 Appliance version  | 
 2019  | 
| 
 Header (eventid)  | 
 Event ID  | 
 700107  | 
| 
 Header (eventName)  | 
 Log name  | 
 Device Access Control  | 
| 
 Header (severity)  | 
 Severity  | 
 3  | 
| 
 rt  | 
 The log generation time in UTC  | 
 Example: "Feb 14 2017 11:14:08 GMT+00:00"  | 
| 
 cs1Label  | 
 Corresponding label for the "cs1" field  | 
 "Product Entity/Endpoint"  | 
| 
 cs1  | 
 Server host name  | 
 Example: "Sample_Host"  | 
| 
 shost  | 
 Source host name  | 
 Example: "shost1"  | 
| 
 dvchost  | 
 Target host name  | 
 Example: "localhost"  | 
| 
 cn1Label  | 
 Corresponding label for the "cn1" field  | 
 "Product"  | 
| 
 cn1  | 
 Product ID  | 
 Example: "Apex One" For more information, see Product ID Mapping Table.  | 
| 
 sproc  | 
 Target process  | 
 Example: "C:\Windows\explorer.exe"  | 
| 
 fname  | 
 File name  | 
 Example: "F:\Autorun.inf"  | 
| 
 cn2Label  | 
 Corresponding label for the "cn2" field  | 
 "Device Type"  | 
| 
 cn2  | 
 Device type  | 
 Example: "0" 
  | 
| 
 cn3Label  | 
 Corresponding label for the "cn3" field  | 
 "Permission"  | 
| 
 cn3  | 
 Permission  | 
 Example: "3" 
  | 
| 
 deviceFacility  | 
 Product  | 
 Example: "Apex One"  | 
Log sample:
CEF:0|Trend Micro|Apex Central|2019|700107|Device Access C ontrol|3|rt=Aug 16 2017 04:49:15 GMT+00:00 cs1Label=Product_ Entity/Endpoint cs1=Sample_Host shost=shost1 dvchost=localho st cn1Label=Product cn1=15 sproc=C:\\Windows\\explorer.exe f name=F:\\Autorun.inf cn2Label=Device_Type cn2=0 cn3Label=Per mission cn3=3 deviceFacility=Apex One
		