Skip to main content
Skip table of contents

Syslog - Trend Micro Deep Discovery Director

Device Details

Device NameTrend Micro Deep Discovery Director

Vendor

Trend Micro

Device Type

Endpoint Security Solution

Supported Model Name/Number

N/A

Supported Software Version

All

Collection Method

Syslog

Configurable Log Output

Yes

Log Source Type

Syslog - Trend Micro Deep Discovery Director

Log Processing Policy

LogRhythm Default V2.0

Exceptions

Only CEF format supported

Additional Information

N/A

Device Configuration Checklist

  • Change Control Manager logging output to the CEF format.
  • Use all other default configuration options.

Supported Log Messages

Type

Product Version

Supported Schema Fields

Attachment Detection EventN/A

<vendorinfo>, <severity>, <threatname>, <hash>, <objecttype>, <object>, <size> 

Deny List Transaction EventN/A<vmid>, <vendorinfo>, <action>, <tag1>, <policy>, <severity>, <dname>, <dport>, <dip>, <hash>, <url>
Disruptive Application EventN/A<vmid>, <vendorinfo>, <severity>, <protname>, <snatip>, <sip>, <dip>, <dnatip>, <dnatip>, <dname>, <dmac>, <dport>, <dip>, <sname>, <smac>, <snatip>, <sport>
Email Detection EventN/A

<vendorinfo>, <severity>, <action>, <tag1>, <size>, <threatname>, <recipient>, <subject>, <sip>, <sender>

File Analysis EventN/A<vendorinfo>, <severity>, <threatname>, <hash>, <objecttype>, <object>, <size> 
Message Tracking EventN/A<vendorinfo>, <severity>, <action>, <tag1>, <status>. <recipient>, <subject>, <reason>, <sip>, <sender>
Notable Characteristics EventN/A

<vendorinfo>, <severity>, <policy>, <hash>, <objecttype>, <object>, <size>, <subject> 

Threat EventN/A<threatid>, <vendorinfo>, <severity>, <action>, <tag1>, <protname>, <snatip>, <sip>, <dip>, <dnatip>,<threatname>, <dnatip>, <dname>, <dmac>, <dport>, <dip>, <recipient>, <hash>, <object>, <size>, <useragent>, <url>, <sname>, <smac>, <snatip>, <sport>, <login>, <sender>
URL Analysis EventN/A<vendorinfo>, <severity>, <hash>, <url>
URL Detection EventN/A<vendorinfo>, <severity>, <threatname>, <url>
Web Reputation EventN/A

<vendorinfo>, <severity>, <protname>, <snatip>, <sip>, <dip>, <dnatip>, <subject>, <threatname>, <dnatip>,<dname>, <dmac>, <dport>, <dip>, <recipient>, <useragent>, <url>, <sname>, <smac>, <snatip>, <sip>, <sport>, <sender> 

Revision History

KB Version

Log Type

Change Type

Details

KB 7.1.646.0SyslogNew DeviceN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.