Syslog Message Format
MetaDefender Core supports to send CEF (Common Event Format) syslog message style
Remote Syslog
[Local Timestamp] [Source IP Address] [UTC Timestamp] [Hostname] [CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension]For example:
Jun 24 14:33:18 192.168.200.223 2019-06-24T14:33:19+07:00 OPSWATPC CEF:0|OPSWAT|MSCL|4.16.0|core.network|MSCL[7548] New maximum agent count is set|2|maxAgentCount='1' msgid=665| Prefix field | Sample value | Description |
|---|---|---|
| Local timestamp | Jun 24 14:33:18 | |
| IP address | 192.168.200.223 | Source IP address ver. 4 |
| UTC timestamp | 2019-06-24T14:33:19+07:00 | |
| Hostname | OPSWATPC | |
| CEF:Version | CEF:0 | Version 0 |
| Device Vendor | OPSWAT | |
| Device Product | MSCL | MSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows |
| Device Version | 4.16.0 | MetaDefender Core version |
| Signature ID | core.network | For example:
|
| Name | MSCL[7548] New maximum agent count is set | Subject of log message
|
| Severity | 2 | Log level
|
| Extension | maxAgentCount='1' msgid=665 | To learn more about msgid (message ID): Error Message Description Table |
Local Syslog
[Local Timestamp] [Hostname] [CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension]For example:
Jun 24 14:33:18 OPSWATPC CEF:0|OPSWAT|MSCL|4.16.0|core.network|MSCL[7548] New maximum agent count is set|2|maxAgentCount='1' msgid=665| Prefix field | Sample value | Description |
|---|---|---|
| Timestamp | Jun 24 14:33:18 | |
| Hostname | OPSWATPC | |
| CEF:Version | CEF:0 | Version 0 |
| Device Vendor | OPSWAT | |
| Device Product | MSCL | MSCL = MetaDefender Core on Linux MSCW = MetaDefender Core on Windows |
| Device Version | 4.16.0 | MetaDefender Core version |
| Signature ID | core.network | For example:
|
| Name | MSCL[7548] New maximum agent count is set | Subject of log message
|
| Severity | 2 | Log level
|
| Extension | maxAgentCount='1' msgid=665 | To learn more about msgid (message ID): Error Message Description Table |
