CEF Key
|
Description
|
Example
|
Header (Device Event Class ID)
|
Unique identifier per event-type
|
|
Header (Device Product)
|
Product of sending device
|
|
Header (Device Vendor)
|
Product vendor
|
|
Header (Device Version)
|
Service version
|
|
Header (Name)
|
Category of the event
|
|
Header (Severity)
|
Importance of the event
|
|
Header (Version)
|
CEF format version
|
|
externalId
|
Workbench ID
|
|
cat
|
Workbench name
|
|
cn1
|
Count of all impact scopes
|
|
cn1Label
|
Corresponding label for the "cn1" field
|
|
cs1
|
Workbench link
|
|
cs1Label
|
Corresponding label for the "cs1" field
|
|
msg
|
Description of the detection model
|
|
rt
|
Workbench complete time
|
|
sourceServiceName
|
Alert provider
|
|
TrendMicroV1CompanyID
|
Company ID
|
|
Views: