Skip to main content
Skip table of contents

V 2.0 : Engine Update Status Event

Vendor Documentation


Rule Name

Rule Type


Common Event

V 2.0 : Engine Update Status EventBase RuleInformationGeneral Information

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AProduct vendor
Header (pname)N/AN/AProduct name
Header (pver)N/AN/AProduct version
Header (eventid)N/A N/AEvent ID
Header (eventName)<vmid> Text/StringLog name
Header (severity)<severity>NumberSeverity
rtN/AN/ALog generation time in UTC
shost<sname>Text/String/NumberProduct Entity/Endpoint
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2<sip>IP AddressProduct/Endpoint IP
cn1LabelN/AN/AConnection status
cn1<status>NumberConnection status
0: Unable to connect
1: Active
2: Inactive
100: Product active
101: Product inactive but agent is active
102: Roaming
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn5LabelN/AN/ACorresponding label for the "cn5" field
cs5<version>Text/String/NumberEngine version
cn3LevelN/AN/ACorresponding label for the "cn3" field
cn3N/AN/AEngine Status
0: Unused
1: In use
cs6LabelN/A N/ACorresponding label for the "cs6" field
cs6N/AN/AActiveUpdate component type
1: Engine
deviceFacilityN/AN/AProduct name
msgN/AN/AEngine type display name
ApexCentralHostN/AN/AApex Central host name
deviceNtDomainN/AN/AActive Directory domain
dntdomN/AN/AApex One domain hierarchy
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.