The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware detection log fields

Prev Next

The Endpoint Security (HX) logs messages when malware is found on a destination host. In addition to the common CEF fields, malware detection logging includes the following fields and field settings:

Malware hit detection

Name: Malware Hit Found
ID: Malware Hit Found
cs4Label: Process Name
cs4: The process or IOC for which the malware was detected
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
cs7Label: Resolution
cs7: The resolution name (for example, ALERT or QUARANTINED)
cs8Label: Alert Types
cs8: malware, spyware, adware, dialer, pup, zipbomb
cs9Label: MD5
cs9: MD5 hash of the malware object
cs10Label: SHA1
cs10: SHA1 hash of the malware object
cs11Label: Malware Signature
cs11: The malware signature
cs12Label: Malware Category
cs12: location of the hit -- boot-sector, registry, or process.
cs13Label: Malware Engine
cs13=AV or MG
act: Detection MAL Hit
externalId: The HX unique identifier associated with this hit
start: Timestamp when the malware was detected on the destination host
categoryOutcome: /Success
categoryBehavior: /Found
categoryDeviceGroup: /IDS
categoryDeviceType: Malware Protection
categoryTechnique: Malware
categoryObject: /Host
categorySignificance: /Compromise
categoryTupleDescription: Malware Protection found a compromise indication
msg: Host <hostname> Malware alert