Skip to main content
Skip table of contents

Syslog - Symantec ICDX CEF

Device Details

Device Name

ICDX

Vendor

Symantec

Device Type

Symantec

Supported Model Name/Number

N/A

Supported Software Version

N/A

Collection Method

Syslog

Configurable Log Output

N/A

Log Source Type

Syslog - Symantec ICDX CEF

Log Processing Policy

LogRhythm Default V 2.0

Exceptions

N/A

Additional Information

https://techdocs.broadcom.com/content/dam/broadcom/techdocs/symantec-security-software/endpoint-security-and-management/integrated-cyber-defense-exchange/generated-pdfs/ICDx_1.4.1_Administration_Guide.pdf

Supported Log Messages

(List of LR tags used to parse the log information for each message type)

Type

Product Version

Supported Schema Fields

Application Lifecycle Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <group>, <login>, <object>, <subject>

Catch All : Level 1

N/A

<tag1>, <severity>

Catch All : Level 2

N/A

<version>, <vmid>, <vendorinfo>, <severity>

Entity Audit Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <login>, <object>, <subject>

File Detection Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <hash>, <parentprocesspath>, <process>, <size>, <threatname>, <policy>, <group>, <login>, <object>, <subject>

Host Network Detection

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <smac>, <reason>, <protnum>, <dport>, <dip>, <sname>, <process>, <sport>, <threatname>, <policy>, <group>, <login>, <object>, <subject>

Process Detection Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <policy>, <group>, <login>, <object>, <subject>

Scan Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <smac>, <policy>, <group>, <login>, <object>, <subject>

Status Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <group>, <login>, <object>, <subject>

Update Messages

N/A

<version>, <vmid>, <vendorinfo>, <severity>, <result>, <tag1>, <objecttype>, <sip>, <sname>, <group>, <login>, <object>, <subject>

Revision History

KB Version

Log Type

Change Type

Details

KB 7.1.723.0

Syslog - Symantec ICDX CEF

New Device Documentation

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.