The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware scan log fields

Prev Next

The Endpoint Security (HX) logs messages when a malware scan is run on an endpoint host. In addition to the common CEF fields, malware scan logging includes the following fields and field settings:

Malware Scan

Name: Malware Scan
ID: Malware Scan
cs2Label: Scan Type
cs2: The type of malware scan (full, quick, or memory)
cs3Label: Scan Time Taken in Seconds
cs3: The scan time, in seconds
cs4Label: Infected Objects Count
cs4: The number of infected objects found during the scan
cs5Label: Actioned Objects Count
cs5: The number of objects for which action is taken
cs6Label: Scanned Objects Count
cs6: The number of objects scanned
cs7Label: Alert Correlation ID
cs7: The hash of the alert ID
act: Malware Scan
msg: Host <host> Malware Scan
externalId: 
start: Timestamp when the malware scan was started on the host endpoint
categoryOutcome: /Success
categoryBehavior: /Scan
categoryDeviceGroup: /IDS
categoryDeviceType: Malware Protection
categoryTechnique: Malware
categoryObject: /Host
categorySignificance: /Scan
categoryTupleDescription: Malware Scan was performed on host.