CEF Key
|
Description
|
Example
|
Header (Device Event Class ID)
|
A unique identifier per event-type
|
|
Header (Device Product)
|
Product of sending device
|
|
Header (Device Vendor)
|
Product vendor
|
|
Header (Device Version)
|
Service version
|
|
Header (Name)
|
Category of the event
|
|
Header (Severity)
|
Importance of the event
|
|
Header (Version)
|
CEF format version
|
|
act
|
Action taken for the violation
|
|
app
|
Network protocol being exploited
|
|
cat
|
Detection name
|
|
cs1
|
MITRE tactics list
|
|
cs1Label
|
Corresponding label for the "cs1" field
|
|
cs2
|
MITRE techniques list
|
|
cs2Label
|
Corresponding label for the "cs2" field
|
|
deviceDirection
|
Device direction
|
|
deviceExternalId
|
GUID of the agent which reported this detection
|
|
deviceFacility
|
Product name
|
|
deviceProcessName
|
Process name in device
|
|
dst
|
Destination IP
|
|
dhost
|
Destination hostname
|
|
dpt
|
Port of "dst"
|
|
dvchost
|
Endpoint hostname
|
|
externalId
|
Event ID
|
|
msg
|
Filter description
|
|
request
|
Notable URL
|
|
rt
|
Event time
|
|
shost
|
Source hostname
|
|
src
|
Source IP
|
|
spt
|
Port of "src"
|
|
TrendMicroV1CompanyID
|
Company ID
|
|
Views: