Table of Contents | ||||||
---|---|---|---|---|---|---|
|
Introduction
The tableTables beginning withcef0.trendmicro.xdr
identifies identify events in CEF format generated by Trendmicro XDRTechnologies.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
cef0.trendMicro.apexCentral
cef0.trendMicro.controlManager
cef0.trendMicro.deepDiscoveryAnalyzer
cef0.trendMicro.deepDiscoveryDirector
cef0.trendMicro.deepDiscoveryInspector
cef0.trendMicro.deepSecurityAgent
cef0.trendMicro.deepSecurityAnalyzer
cef0.trendmicrotrendMicro.xdrdeepSecurityManager
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in this table:
cef0.
...
trendMicro.
...
apexCentral
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
hostname |
|
| |
priorityCode |
|
| |
cefTag |
|
| |
cefVersion |
|
| |
embDeviceVendor |
|
| |
embDeviceProduct |
|
| |
deviceVersion |
|
| |
signatureID |
|
| |
name |
|
| |
severity |
|
| |
act |
|
| |
app |
|
| |
cat |
|
| |
cn1 |
|
| |
cn1Label |
|
| |
cn2 |
|
| |
cn2Label |
|
| |
cn3 |
|
| |
cn3Label |
|
| |
cn4 |
|
| |
cn4Label |
|
| |
cnt |
|
| |
cs1 |
|
| |
cs1Label |
|
| |
cs2 |
|
| |
cs2Label |
|
| |
cs3 |
|
| |
cs3Label |
|
| |
cs4 |
|
| |
cs4Label |
|
| |
cs5 |
|
| |
cs5Label |
|
| |
cs6 |
|
| |
cs6Label |
|
| |
deviceDirection |
|
| |
deviceExternalId |
|
| |
deviceFacility |
|
| |
dhost |
|
| |
dmac |
|
| |
dpt |
|
| |
dst |
|
| |
duser |
|
| |
dvchost |
|
| |
fileHash |
| ||
fname |
|
| |
proto |
| ||
reason |
| ||
rt |
| ||
shost |
| ||
smac |
| ||
sourceServiceName |
| ||
spt |
| ||
src |
| ||
suser |
| ||
deviceNtDomain |
| ||
dntdom |
| ||
request |
| ||
deviceProcessName |
| ||
hostchain |
| ✓ | |
tag |
| cefTag | ✓ |
rawMessage |
|
cef0.trendMicro.controlManager
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
rawMessage |
|
| ✓ |
hostchain |
|
| ✓ |
priorityCode |
|
| |
cefTag |
|
| |
cefVersion |
|
| |
embDeviceVendor |
|
| |
embDeviceProduct |
|
| |
deviceVersion |
|
| |
signatureID |
|
| |
name |
|
| |
severity |
|
| |
_cefVer |
|
| |
act |
|
| |
app |
|
| |
cat |
|
| |
c6a1Label |
|
| |
c6a1 |
|
| |
c6a2Label |
|
| |
c6a2 |
|
| |
c6a3Label |
|
| |
c6a3 |
|
| |
c6a4Label |
|
| |
c6a4 |
|
| |
cfp1Label |
|
| |
cfp1 |
|
| |
cfp2Label |
|
| |
cfp2 |
|
| |
cfp3Label |
|
| |
cfp3 |
|
| |
cfp4Label |
|
| |
cfp4 |
|
| |
cn1Label |
|
| |
cn1 |
|
| |
cn2Label |
|
| |
cn2 |
|
| |
cn3Label |
|
| |
cn3 |
|
| |
cnt |
|
| |
cs1Label |
|
| |
cs1 |
|
| |
cs2Label |
|
| |
cs2 |
|
| |
cs3Label |
|
| |
cs3 |
| ||
cs4Label |
|
| |
cs4 |
| ||
cs5Label |
| ||
cs5 |
| ||
cs6Label |
| ||
cs6 |
| ||
destinationDnsDomain |
| ||
destinationServiceName |
| ||
destinationTranslatedAddress |
| ||
destinationTranslatedPort |
| ||
deviceCustomDate1Label |
| ||
deviceCustomDate1 |
| ||
deviceCustomDate2Label |
| ||
deviceCustomDate2 |
| ||
deviceDirection |
| ||
deviceDnsDomain |
|
| |
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceMacAddress |
| ||
deviceNtDomain |
| ||
deviceOutboundInterface |
| ||
deviceProcessName |
| ||
deviceTranslatedAddress |
| ||
dhost |
| ||
dmac |
| ||
dntdom |
| ||
dpid |
| ||
dpriv |
| ||
dproc |
| ||
dst |
| ||
duid |
| ||
duser |
| ||
dvchost |
| ||
dvc |
| ||
dvcpid |
| ||
end |
| ||
deviceFacility |
| ||
externalId |
| ||
fileCreateTime |
| ||
fileHash |
| ||
fileId |
| ||
fileModificationTime |
| ||
filePath |
| ||
filePermission |
| ||
fileType |
| ||
fname |
|
msg
str
rt
timestamp
shost
str
suid
str
ad_cn4
str
ad_cn4Label
str
agentZoneURI
str
agt
str
ahost
str
aid
str
amac
str
art
str
at
str
atz
str
av
str
customerURI
str
deviceSeverity
str
dtz
str
eventId
str
geid
str
hostchain
str
✓
tag
str
fsize |
| ||
in |
| ||
msg |
| ||
oldFileCreateTime |
| ||
oldFileHash |
| ||
oldFileId |
| ||
oldFileModificationTime |
| ||
oldFileName |
| ||
oldFilePath |
| ||
oldFilePermission |
| ||
oldFileSize |
| ||
oldFileType |
| ||
outcome |
| ||
out |
| ||
proto |
| ||
reason |
| ||
requestClientApplication |
| ||
requestCookies |
| ||
requestMethod |
| ||
request |
| ||
rt |
| ||
shost |
| ||
smac |
| ||
sntdom |
| ||
sourceDnsDomain |
| ||
sourceServiceName |
| ||
sourceTranslatedAddress |
| ||
sourceTranslatedPort |
| ||
spid |
| ||
spriv |
| ||
sproc |
| ||
spt |
| ||
src |
| ||
start |
| ||
suid |
| ||
suser |
| ||
catdt |
| ||
deviceDomain |
| ||
deviceSeverity |
| ||
dpt |
| ||
dtz |
| ||
dvcmac |
| ||
endTime |
| ||
eventId |
| ||
flexNumber1 |
| ||
flexNumber1Label |
| ||
flexNumber2 |
| ||
flexNumber2Label |
| ||
flexString1 |
| ||
flexString1Label |
| ||
flexString2 |
| ||
flexString2Label |
| ||
modelConfidence |
| ||
priority |
| ||
relevance |
| ||
requestContext |
| ||
sessionId |
| ||
slat |
| ||
slong |
| ||
dlat |
| ||
dlong |
| ||
sourceGeoCountryCode |
| ||
sourceGeoLocationInfo |
| ||
sourceGeoPostalCode |
| ||
sourceGeoRegionCode |
| ||
destinationGeoCountryCode |
| ||
destinationGeoLocationInfo |
| ||
destinationGeoPostalCode |
| ||
destinationGeoRegionCode |
| ||
agt |
| ||
ahost |
| ||
art |
| ||
atz |
| ||
mrt |
| ||
categoryBehavior |
| ||
categoryCustomFormatField |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
categoryTechnique |
| ||
categoryTupleDescription |
| ||
assetCriticality |
| ||
customerID |
| ||
customerURI |
| ||
tag |
| cefTag | ✓ |
cef0.trendMicro.deepDiscoveryAnalyzer
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
hostname |
|
| ✓ |
priorityCode |
|
| ✓ |
cefTag |
|
| |
cefVersion |
|
| |
embDeviceVendor |
|
| |
embDeviceProduct |
|
| |
deviceVersion |
|
| |
signatureID |
|
| |
name |
|
| |
severity |
|
| |
_cefVer |
|
| |
act |
|
| |
app |
|
| |
cn1Label |
|
| |
cn1 |
|
| |
cn2Label |
|
| |
cn2 |
|
| |
cn3Label |
|
| |
cn3 |
|
| |
cs1Label |
|
| |
cs1 |
|
| |
cs2Label |
|
| |
cs2 |
|
| |
cs3Label |
|
| |
cs3 |
|
| |
cs4Label |
|
| |
cs4 |
|
| |
cs5Label |
|
| |
cs5 |
|
| |
deviceDirection |
|
| |
deviceExternalId |
|
| |
dhost |
|
| |
dmac |
|
| |
dst |
|
| |
dpt |
|
| |
duser |
|
| |
dvchost |
|
| |
dvc |
|
| |
dvcmac |
|
| |
end |
|
| |
fileHash |
|
| |
fileType |
|
| |
fname |
|
| |
fsize |
| ||
msg |
|
| |
outcome |
| ||
requestClientApplication |
| ||
request |
| ||
rt |
| ||
shost |
| ||
smac |
| ||
src |
| ||
spt |
| ||
s3Label |
| ||
hostchain |
| ✓ | |
tag |
| cefTag | ✓ |
rawMessage |
|
✓ |