The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

fenotify rsyslog default format

Prev Next

Sets the default delivery format for rsyslog notifications.

Syntax

[no] fenotify rsyslog default format <format-type>

Parameters

no

Use the no form of this command to remove the default setting.

format-type

The following default delivery formats are supported:

  • cef—Delivery in common event format (CEF).

  • csv—Delivery in comma-separated values (CSV) format.

  • leef—Delivery in log event enhanced format (LEEF).

Select one of the Text, JSON (JavaScript Object Notation), or XML options:

  • json-concise—Sends a notification in JSON CONCISE format containing basic information such as Alert type, ID, src_IP, malware name, hostname, and Alert URL.

  • json-extended—Sends a notification in JSON EXTENDED format containing detailed information and abstracts including data-theft information (if any) and static analysis details. JSON Extended provides all details about files and objects modified during analysis.

  • json-normal—Sends a notification in JSON NORMAL format containing detailed information and abstracts such as Alert type, ID, src_IP, malware name, hostname, and Alert URL without any redundant information.

  • json-legacy-concise—Sends a notification in JSON legacy CONCISE format containing basic information such as Alert type, ID, src_IP, malware name, hostname, and Alert URL.

  • json-legacy-extended—Sends a notification in JSON legacy EXTENDED format containing detailed information and abstracts including data-theft information (if any) and static analysis details. JSON legacy Extended provides all details about files and objects modified during analysis.

  • json-legacy-normal—Sends a notification in JSON legacy NORMAL format containing detailed information and abstracts such as Alert type, ID, src_IP, malware name, hostname, and Alert URL without any redundant information.

  • text-concise—Sends a notification in TEXT CONCISE format containing basic information such as Alert type, ID, src_IP, malware name, hostname, and Alert URL.

  • text-extended—Sends a notification in TEXT EXTENDED format containing detailed information and abstracts including data-theft information (if any) and static analysis details. TEXT Extended provides all details about files and objects modified during analysis.

  • ext-normal—Delivery in TEXT NORMAL format containing detailed information and abstracts such as Alert type, ID, src_IP, malware name, hostname, and Alert URL without any redundant information.

  • xml-concise—Sends a notification in XML CONCISE format containing basic information such as Alert type, ID, src_IP, malware name, hostname, and Alert URL.

  • xml-extended—Sends a notification in XML EXTENDED format containing detailed information and abstracts including data-theft information (if any) and static analysis details. XML Extended provides all details about files and objects modified during analysis.

  • xml-normal—Sends a notification in XML NORMAL format containing detailed information and abstracts such as Alert type, ID, src_IP, malware name, hostname, and Alert URL without any redundant information.

  • secureworks—Sends a notification in SecureWorks format.

Example

The following example sets the default deliver format to CEF:

hostname (config) # fenotify rsyslog default format cef

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Before release 7.6

  • Endpoint Security (HX): Release 3.5.0

  • File Protect: Before release 7.6

  • Malware Analysis: Before release 7.6

  • Network Security: Before release 7.6