The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Quarantine file user action log fields

Prev Next

When a user attempts to delete or restore a file from the malware quarantine area, CEF log messages are written.

CEF log entries are also written when the agent automatically attempts to perform malware remediation on a file in which malware has been detected. See Malware automatic remediation log fields . In addition, CEF log entries are written when a file ages out of the quarantine area. See Quarantine File Aging Log Fields

Deleting a quarantined file

When a user attempts to delete a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:

cs3Label: Quarantine Action
cs3: delete
request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/delete

Restoring a quarantined file

When a user attempts to restore a quarantined file, malware logging includes the following fields and field settings, in addition to the common CEF fields and the common quarantine file user action fields:

cs3Label: Quarantine Action
cs3: restore
request: https://<HX_HOSTNAME>:<HX_UI_PORT>/hx/api/v3/quarantines/ <quarantine_id>/restore

Common quarantine file user action fields

The following fields are common to all quarantine file user action CEF log entries.

Name: FireEye Quarantine Request
ID: FireEye Quarantine Request
cs4Label: Quarantine ID
cs4: The unique ID for the quarantine
cs5Label: Target GMT Offset 
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event or the SHA1 hash
act: Quarantine <host> request <Queued | Success | Failed>
msg: Host <host> quarantine request <Queued | Success | Failed>
externalId: Task ID used to track the requested task in the database
start: Timestamp for the start of the remediation attempt on the destination host
categoryOutcome: </Success | /Failure>
categoryBehavior: <Queued | Success | Failed | /Access/Start>
categoryDeviceGroup: /IDS/Application/Service
categoryDeviceType: Forensic Investigation
categoryObject: /Host
categorySignificance: </Informational | /Informational/error>
categoryTupleDescription: <action> request.