Skip to main content
Skip table of contents

Syslog - Apex One

Device Details

Vendor

Trend Micro

Device Type

Endpoint Security Solution

Supported Model Name/Number

N/A

Supported Software Version

All

Collection Method

Syslog

Configurable Log Output

Yes

Log Source Type

Syslog - Apex One

Log Processing Policy

LogRhythm Default

Exceptions

Only CEF format supported

Additional Information

Supported Log Types and Formats

CEF Data Loss Prevention Logs

Apex Central 2019 - Best Practice Guide

Device Configuration Checklist

  • Change Control Manager logging output to the CEF format
  • Use all other default configuration options

Currently Supported Log Types

Type

Version

Supported Schema Fields

File Logging Information Messages

All

<severity>, <version>, <vendorinfo>, <threatname>, <dname>, <action>, <policy>, <reason>, <processid>, <sname>, <object>, <parentprocesspath>, <dip>, <hash>

Behavior Monitoring Log Messages

All

<severity>, <version>, <vendorinfo>, <action>, <dname>, <policy>, <parentprocesspath>, <process>, <result>, <sname>, <sip>

Device Access Control Log Messages

All

<severity>, <version>, <vendorinfo>, <action>, <sname>, <dname> , <process>, <object>, <command>

Parsed Metadata Fields

Device Field NameLogRhythm Metadata FieldValue/Data Type
actActionText/String
catProcessIDNumber/String
cn2ObjectText/String
cn3CommandText/String
cs1PolicyText/String
cs4ObjectTypeText/String
deviceFacilityObjectNameText/String
dhostDNameText/String
dstDIPIP Address
dvchostSNameText/String
dvchostDNameText/String
filehashHashText/String
filepathObject/ParentProcessPathText/String
fnameObjectText/String
severitySeverityText/String
sprocParentProcessPath/ProcessText/String
srcSIPIP Address
threatnameThreatNameText/String
vendorinfoVendorInfoText/String
versionVersionNumber
vmid/deviceExternalIdVMID/VendorInfoNumber/Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.