The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Indicator hit detection log fields

Prev Next

The Endpoint Security (HX) logs messages when indicator of compromise (IOC) rules are found on a destination host. In addition to the common CEF fields, indicator hit detection logging includes the following fields and field settings:

IOC hit detection

Name: IOC Hit Found
ID: IOC Hit Found
cs4Label: IOC Name
cs4: Name of the HX threat that was found on the destination host
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
act: Detection IOC Hit
externalId: The HX unique identifier associated with this hit
start: Timestamp when the indicator was detected on the destination host
categoryOutcome: /Success
categoryBehavior: /Found
categoryDeviceGroup: /IDS
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: /Compromise
categoryTechnique: Alert
categoryTupleDescription: A Detection IOC found a compromise indication
msg: Host <hostname> IOC compromise