Syslog Message Format

MetaDefender Core supports to send CEF (Common Event Format) syslog message style

Remote Syslog

log format
Copy

For example:

log example
Copy
Prefix fieldSample valueDescription
Local timestampJun 24 14:33:18
IP address192.168.200.223Source IP address ver. 4
UTC timestamp2019-06-24T14:33:19+07:00
HostnameOPSWATPC
CEF:VersionCEF:0Version 0
Device VendorOPSWAT
Device ProductMSCLMSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows
Device Version4.16.0MetaDefender Core version
Signature IDcore.network

For example:

  • core.network: Component "network" on "Core" module
  • agent.engines: Component "engines" on "Node"
  • common.update: Component "update" on common module shared by all modules
NameMSCL[7548] New maximum agent count is set

Subject of log message

  • MSCL[7548] = MetaDefender Core on Linux ["ometascan" process id = 7548]
  • ometascan-node[455] = MetaDefender Core Node ["ometascan-node" process id = 455]
Severity2

Log level

  • DUMP (0): The most verbose severity level, these entries are for debuggers only.
  • DEBUG (1): Debuggers severity level, mostly used by support issues.
  • INFO (2): Information from the software, such as scan results.
  • WARNING (3): A problem occurred needs investigation and OPSWAT support must be contacted, however the product is supposed to be operational.
  • ERROR (4): Software error happened, please contact support if the issue is persist. Software functionality may be downgraded in these cases.
ExtensionmaxAgentCount='1' msgid=665To learn more about msgid (message ID): Error Message Description Table

Local Syslog

log format
Copy

For example:

log example
Copy
Prefix fieldSample valueDescription
TimestampJun 24 14:33:18
HostnameOPSWATPC
CEF:VersionCEF:0Version 0
Device VendorOPSWAT
Device ProductMSCLMSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows
Device Version4.16.0MetaDefender Core version
Signature IDcore.network

For example:

  • core.network: Component "network" on "Core" module
  • agent.engines: Component "engines" on "Node"
  • common.update: Component "update" on common module shared by all modules
NameMSCL[7548] New maximum agent count is set

Subject of log message

  • MSCL[7548] = MetaDefender Core on Linux ["ometascan" process id = 7548]
  • ometascan-node[455] = MetaDefender Core Node ["ometascan-node" process id = 455]
Severity2

Log level

  • DUMP (0): The most verbose severity level, these entries are for debuggers only.
  • DEBUG (1): Debuggers severity level, mostly used by support issues.
  • INFO (2): Information from the software, such as scan results.
  • WARNING (3): A problem occurred needs investigation and OPSWAT support must be contacted, however the product is supposed to be operational.
  • ERROR (4): Software error happened, please contact support if the issue is persist. Software functionality may be downgraded in these cases.
ExtensionmaxAgentCount='1' msgid=665To learn more about msgid (message ID): Error Message Description Table
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard