Audit CEF Fields
Table of Contents
Audit CEF Fields
The following table identifies the Audit field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
Event Category
| Query Name: event_categoryHeader Type: Custom |
Event Description
| Query Name: event_descriptionHeader Type: Custom |
Event Destination URL
| Query Name: event_dest_urlHeader Type: Custom |
Destination Vendor
| Query Name: event_dest_vendorHeader Type: Custom |
Event Details
| Query Name: event_detailHeader Type: Custom |
Event Name
| Query Name: event_nameHeader Type: Custom |
Event Result
| Query Name: event_resultHeader Type: Custom |
Event Time
| Query Name: event_timeHeader Type: Custom |
Log Source
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| |
Log Source ID
| Query Name: log_source_idHeader Type: Custom |
Log Time
| Query Name: log_timeHeader Type: Custom |
Log Type
| Query Name: log_type.valueHeader Type: Custom |
PlatformType
| Query Name: platform_typeHeader Type: Custom |
Subtype
| Query Name: sub_type.valueHeader Type: Custom |
Vendor Name
| Query Name: vendor_nameHeader Type: Custom |
Vendor Severity
| Query Name: vendor_severity.valueHeader Type: Custom |