The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Common log fields

Prev Next

All CEF logs contain the following fields, in addition to fields for specific logs:

Time: Timestamp of log entry
Device Vendor: fireeye
Device Product: hx
Device Version: ADD LONG SW RELEASE
Name: A description of the logged event
ID: The same as Name value
Log Message Type:
0: Informational message
4: Warning message
7: Permanent acquisition error message
10: Any FireEye endpoint hit (alert), such as an IOC, malware, or exploit hit
             
rt: The time the event was recorded on the appliance
dvchost: Hostname of the Endpoint Security server
deviceExternalId: Appliance ID of the Endpoint Security server
cs1Label: Host Agent Cert Hash
cs1: The host agent certificate hash of the host generating the event
dst: The primary IP address of the host generating the event
dmac: The MAC address of the host generating the event
dhost: The name of the host generating the event
dntdom: The domain of the host generating the event
deviceCustomDate1Label: "Agent Last Sysinfo" or "Agent Last Audit"
deviceCustomDate1: Last system audit of the host generating the event
cs2Label: FireEye Agent Version
cs2: The version number of the agent on the host generating the event
cs5Label: Target GMT Offset, Correlation ID (remediation), or Actioned Objects Count (malware scans)
cs5: The GMT offset of the host generating the event in ISO 8601 duration format, the alert correlation ID for a malware quarantine attempt, or the number of scanned objects for which action is taken.
cs6Label: Target OS, SHA1 (remediation), or Scanned Objects Count (malware scans)
cs6: The operating system of the host generating the event, the SHA1 hash of the quarantined file, or the number of objects scanned for malware.
externalId: A reference number assigned to related events; events sharing the same ID should be considered connected
categoryOutcome: The agent outcome 
categorySignificance: The significance of the event
categoryBehavior: The agent behavior
cs7Label: Resolution
cs7: The result of the hit
cd8Label: Alert Types
cs8: The types of alert produced by the hit
msg: A text description of the event