The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

CEF standard fields and values for Email Security — Cloud Edition

Prev Next

Note

If the field value is not present, that field is not part of the CEF notification.

  • The following table describes the CEF fields and values used for Email Security - Cloud Edition notifications.

Field

Value

Type

Mandatory

Variable

Length

Notes

CEF

CEF

String

Yes

No

—

—

Version

0

Int

Yes

No

—

—

Device Vendor

Trellix

String

Yes

No

—

—

Device Product

Email Security - Cloud

String

Yes

No

—

—

Device Version

3.0

String

Yes

No

—

This string might increment in subsequent releases.

Device Event Class ID

etp

String

Yes

No

—

—

Name

malicious email/ace

String

Yes

Yes

—

—

Severity

Value is between 1 and 10.

Number

Yes

No

—

—

rt

Date in the following format:

MMM dd yyyy HH:mm:ss UTC

Date

Yes

Yes

—

Timestamp at which the alert was generated in UTC.

suser

Sender email address

String

Yes

Yes

1023 characters

—

duser

Destination email address

String

Yes

Yes

1023 characters

—

request

Malicious URL

String

No

Yes

1023 characters

—

fname

Malware file name

String

No

Yes

1023 characters

—

fileHash

Hash value of the file/URL

String

Yes

Yes

255 characters

The format is MD5.

destinationDnsDomain

Destination email address domain

String

Yes

Yes

255 characters

—

externalId

Database alert ID

String

Yes

Yes

255 characters

—

cs1Label

sname

String

Yes

No

1023 characters

—

cs1

Trellix malware name

String

Yes

Yes

400 characters

—

cs3Label

Subject

String

Yes

No

1023 characters

—

cs3

Message subject

String

Yes

Yes

4000 characters

—

cs4Label

Link

String

Yes

No

1023 characters

—

cs4

URL to the alert page on the Email Security - Cloud portal

String

Yes

Yes

4000 characters

—

cs5Label

Client

String

Yes

No

1023 characters

—

cs5

Customer ID

String

Yes

Yes

4000 characters

—

cs6Label

Trellix Advanced Threat Intelligence name, type, and level

String

No

No

1023 characters

—

cs6

Data extracted from the Trellix Advanced Threat Intelligence service

String

No

Yes

4000 characters

—

flexString1Label

Trellix Advanced Threat Intelligence threat attribution

String

No

No

128 characters

—

flexString1

Data extracted from the Trellix Advanced Threat Intelligence service

String

No

Yes

1023 characters

—