Skip to main content
Skip table of contents

V 2.0 : Virus/Malware Logs

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : Virus/Malware LogsBase RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : UnknownSub RuleOther SecurityGeneral Security
V 2.0 : Virus/Malware : Not ApplicableSub RuleOther SecurityGeneral Security
V 2.0 : Virus/Malware : File CleanedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : File DeletedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : File QuarantinedSub RuleActivityQuarantine
V 2.0 : Virus/Malware : File RenamedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : File PassedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : Unable To Clean File, PassedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : Unable To Clean File, DeletedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : Unable To Clean File, RenamedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/MW : Unable To Clean File, QuarantinedSub RuleActivityQuarantine
V 2.0 : Virus/Malware : Unable To Clean File, StrippedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : File ReplacedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : File DroppedSub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : File ArchivedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : Blocked SuccessfullySub RuleFailed MalwareFailed Malware Activity
V 2.0 : Virus/Malware : Quarantined SuccessfullySub RuleActivityQuarantine
V 2.0 : Virus/Malware : Stamped SuccessfullySub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : File UploadedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : Access DeniedSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : No ActionSub RuleMalwareDetected Malware Activity
V 2.0 : Virus/Malware : Scan StoppedSub RuleInformationScan Stopped
V 2.0 : Virus/Malware : EncryptedSub RuleActivityEncrypted Files Detected
V 2.0 : Virus/Malware : UndefinedSub RuleActivityGeneral Activity
V 2.0 : Virus/Malware : System RebootedSub RuleStartup and ShutdownSystem Restarted
V 2.0 : Virus/Malware : Action FailedSub RuleActivityGeneral Activity
V 2.0 : Virus/Malware : Action RequiredSub RuleActivityGeneral Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)<vmid>Text/StringAV:Action
Header (eventName)<threatname>Text/StringVirus/Malware name
Header (severity)<severity>NumberSeverity
deviceExternalIdN/AN/AID
rtN/AN/ALog generation time in UTC
cnt<quantity>NumberDetections
dhost<dname>Text/StringEndpoint
duser<account>Text/String/NumberUser
act<action>
<tag1>
Text/StringAction
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1N/AN/APattern/Rule version
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2N/AN/ASecond action
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1N/AN/A0: Unknown
1: N/A
11: Real-time Scan
12: Manual Scan
13: Scheduled Scan
16: Scan Now
17: Card Scan
18: Damage Cleanup Services
19: Storage Scan
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2N/AN/AEngine version
cs3LabelN/AN/ACorresponding label for the "cs3" field
cs3<version>NumberProduct version
cs4LabelN/AN/ACorresponding label for the "cs4" field
cs4N/AN/AReason code
cs5LabelN/AN/ACorresponding label for the "cs5" field
cs5<result>Text/StringFirst action result
cs6LabelN/AN/ACorresponding label for the "cs6" field
cs6N/AN/ASecond action result
catN/AN/ALog type
dvchostN/AN/AProduct server name
cn3LabelN/AN/ACorresponding label for the "cn3" field
cn3N/AN/A0: Low
1: Low
2: Medium
3: High
fname<object>Text/StringFile
filePathN/AN/AFile path
msg<subject>Text/StringFile in compressed file
shost<sname>Text/String/NumberSource host
suser<login>Text/String/NumberSource host
dst<dip>IP AddressEndpoint IPv4 address
fileHash<hash>Text/String/NumberFile SHA-1
deviceFacilityN/AN/AProduct name
reason<reason>Text/StringCritical Threat Type
A: Known Advanced Persistent Threat (APT)
B: Social engineering attack
C: Vulnerability attack
D: Lateral movement
E: Unknown threats
F: C&C callback
G: Ransomware
deviceNtDomainN/AN/AActive Directory domain
dntdomN/AN/AApex One domain hierarchy
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.