Syslog Message Format
MetaDefender Core supports to send CEF (Common Event Format) syslog message style
Remote Syslog
[Local Timestamp] [Source IP Address] [UTC Timestamp] [Hostname] [CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension]
For example:
Jun 24 14:33:18 192.168.200.223 2019-06-24T14:33:19+07:00 OPSWATPC CEF:0|OPSWAT|MSCL|4.16.0|core.network|MSCL[7548] New maximum agent count is set|2|maxAgentCount='1' msgid=665
Prefix field | Sample value | Description |
---|---|---|
Local timestamp | Jun 24 14:33:18 | |
IP address | 192.168.200.223 | Source IP address ver. 4 |
UTC timestamp | 2019-06-24T14:33:19+07:00 | |
Hostname | OPSWATPC | |
CEF:Version | CEF:0 | Version 0 |
Device Vendor | OPSWAT | |
Device Product | MSCL | MSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows |
Device Version | 4.16.0 | MetaDefender Core version |
Signature ID | core.network | For example:
|
Name | MSCL[7548] New maximum agent count is set | Subject of log message
|
Severity | 2 | Log level
|
Extension | maxAgentCount='1' msgid=665 | To learn more about msgid (message ID): Error Message Description Table |
Local Syslog
[Local Timestamp] [Hostname] [CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension]
For example:
Jun 24 14:33:18 OPSWATPC CEF:0|OPSWAT|MSCL|4.16.0|core.network|MSCL[7548] New maximum agent count is set|2|maxAgentCount='1' msgid=665
Prefix field | Sample value | Description |
---|---|---|
Timestamp | Jun 24 14:33:18 | |
Hostname | OPSWATPC | |
CEF:Version | CEF:0 | Version 0 |
Device Vendor | OPSWAT | |
Device Product | MSCL | MSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows |
Device Version | 4.16.0 | MetaDefender Core version |
Signature ID | core.network | For example:
|
Name | MSCL[7548] New maximum agent count is set | Subject of log message
|
Severity | 2 | Log level
|
Extension | maxAgentCount='1' msgid=665 | To learn more about msgid (message ID): Error Message Description Table |
Was this page helpful?