Azure-Sentinel/Sample Data/CEF/Forcepoint Cloud Security G...

8.0 KiB

1TenantIdSourceSystemTimeGenerated [UTC]ReceiptTimeDeviceVendorDeviceProductDeviceEventClassIDLogSeverityOriginalLogSeverityDeviceActionSimplifiedDeviceActionComputerCommunicationDirectionDeviceFacilityDestinationPortDestinationIPDeviceAddressDeviceNameMessageProtocolSourcePortSourceIPRemoteIPRemotePortMaliciousIPThreatSeverityIndicatorThreatTypeThreatDescriptionThreatConfidenceReportReferenceLinkMaliciousIPLongitudeMaliciousIPLatitudeMaliciousIPCountryDeviceVersionActivityApplicationProtocolEventCountDestinationDnsDomainDestinationServiceNameDestinationTranslatedAddressDestinationTranslatedPortDeviceDnsDomainDeviceExternalIDDeviceInboundInterfaceDeviceNtDomainDeviceOutboundInterfaceDevicePayloadIdProcessNameDeviceTranslatedAddressDestinationHostNameDestinationMACAddressDestinationNTDomainDestinationProcessIdDestinationUserPrivilegesDestinationProcessNameDeviceTimeZoneDestinationUserIDDestinationUserNameDeviceMacAddressProcessIDExternalIDFileCreateTimeFileHashFileIDFileModificationTimeFilePathFilePermissionFileTypeFileNameFileSizeReceivedBytesOldFileCreateTimeOldFileHashOldFileIDOldFileModificationTimeOldFileNameOldFilePathOldFilePermissionOldFileSizeOldFileTypeSentBytesRequestURLRequestClientApplicationRequestContextRequestCookiesRequestMethodSourceHostNameSourceMACAddressSourceNTDomainSourceDnsDomainSourceServiceNameSourceTranslatedAddressSourceTranslatedPortSourceProcessIdSourceUserPrivilegesSourceProcessNameSourceUserIDSourceUserNameEventTypeDeviceCustomIPv6Address1DeviceCustomIPv6Address1LabelDeviceCustomIPv6Address2DeviceCustomIPv6Address2LabelDeviceCustomIPv6Address3DeviceCustomIPv6Address3LabelDeviceCustomIPv6Address4DeviceCustomIPv6Address4LabelDeviceCustomFloatingPoint1DeviceCustomFloatingPoint1LabelDeviceCustomFloatingPoint2DeviceCustomFloatingPoint2LabelDeviceCustomFloatingPoint3DeviceCustomFloatingPoint3LabelDeviceCustomFloatingPoint4DeviceCustomFloatingPoint4LabelDeviceCustomNumber1DeviceCustomNumber1LabelDeviceCustomNumber2DeviceCustomNumber2LabelDeviceCustomNumber3DeviceCustomNumber3LabelDeviceCustomString1DeviceCustomString1LabelDeviceCustomString2DeviceCustomString2LabelDeviceCustomString3DeviceCustomString3LabelDeviceCustomString4DeviceCustomString4LabelDeviceCustomString5DeviceCustomString5LabelDeviceCustomString6DeviceCustomString6LabelDeviceCustomDate1DeviceCustomDate1LabelDeviceCustomDate2DeviceCustomDate2LabelFlexDate1FlexDate1LabelFlexNumber1FlexNumber1LabelFlexNumber2FlexNumber2LabelFlexString1FlexString1LabelFlexString2FlexString2LabelAdditionalExtensionsStartTime [UTC]EndTime [UTC]Type_ResourceId
2ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:47.092 AMForcepoint CSGWeb"Productivity Loss0Authentication RequiredAuthentication Required168.63.129.1610.0.100.41NoneHTTPUnknownHealthService0890HTTP://168.63.129.16/HealthServiceNonePostNot availableWeb HostingCategory Name168.63.129.16Domain name of the destination siteCork BizDevPolicy Name52.136.205.45IP address of connection to the cloud service.NoneCloud App Risk Level2020-12-10T10:20:03.000ZLog Created Time Netherlands - Amsterdam (X)The cloud service data center that processed therequest.CommonSecurityLog
3ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:47.421 AMForcepoint CSGWeb"Productivity Loss0Authentication RequiredAuthentication Required168.63.129.1610.0.100.41NoneHTTPUnknownmachine0669HTTP://168.63.129.16/machine?comp\=goalstateNoneGetNot availableWeb HostingCategory Name168.63.129.16Domain name of the destination siteCork BizDevPolicy Name52.136.205.45IP address of connection to the cloud service.NoneCloud App Risk Level2020-12-10T10:21:05.000ZLog Created Time Netherlands - Amsterdam (X)The cloud service data center that processed therequest.CommonSecurityLog
4ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:47.476 AMForcepoint CSGWeb"Productivity Loss0BlockedBlocked168.63.129.1652.136.205.451NoneHTTPUnknownHealthService0429HTTP://168.63.129.16/HealthServiceNonePostNot availableWeb HostingCategory Name168.63.129.16Domain name of the destination siteCork BizDevPolicy Name52.136.205.45IP address of connection to the cloud service.NoneCloud App Risk Level2020-12-10T10:21:06.000ZLog Created Time Netherlands - Amsterdam (X)The cloud service data center that processed therequest.CommonSecurityLog
5ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:47.530 AMForcepoint CSGWeb"Productivity Loss0Authentication RequiredAuthentication Required168.63.129.1610.0.100.41NoneHTTPUnknownHealthService0890HTTP://168.63.129.16/HealthServiceNonePostNot availableWeb HostingCategory Name168.63.129.16Domain name of the destination siteCork BizDevPolicy Name52.136.205.45IP address of connection to the cloud service.NoneCloud App Risk Level2020-12-10T10:21:05.000ZLog Created Time Netherlands - Amsterdam (X)The cloud service data center that processed therequest.CommonSecurityLog
6ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:49.185 AMForcepoint CSGEmailBusiness Usage0AcceptedAccepted1Warning: could not send message for past 4 hours127.0.0.11CSG EMail39LXRXxQKBKsRZZRWPLWPced-YZcPaWjRZZRWP.NZXUOZPWLMdP.Pf@alerts.bounces.google.comNone"None0Mail Delivery SubsystemMAILER-DAEMON@rly10d.srv.mailcontrol.com0Spam Score27707Message SizeNoneBlack/white listedNoneVirus NameDEFAULTPolicy NameNoneAdvanced Encryption2020-12-10T10:14:25.000ZLog Created Time CleanFiltering ReasonCommonSecurityLog
7ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:49.497 AMForcepoint CSGEmailBusiness Usage0AcceptedAccepted0Alerte Google : South Africa209.85.219.1981CSG EMailjdoe@labse.euNone"None0Google Alertsgooglealerts-noreply@google.com-105.4Spam Score14767Message SizeNoneBlack/white listedNoneVirus NameDEFAULTPolicy NameNoneAdvanced Encryption2020-12-10T10:15:58.000ZLog Created Time CleanFiltering ReasonCommonSecurityLog
8ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:49.878 AMForcepoint CSGEmailProductivity Loss0AcceptedAccepted0Alerte Google : Israel209.85.219.1981CSG EMailjdoe@labse.euNone"None0Google Alertsgooglealerts-noreply@google.com-105.6Spam Score44172Message SizeNoneBlack/white listedNoneVirus NameDEFAULTPolicy NameNoneAdvanced Encryption2020-12-10T10:15:58.000ZLog Created Time CleanFiltering ReasonCommonSecurityLog
9ad1f026a-17e7-4fa8-82df-9cd9d3d3b320OpsManager12/10/2020, 10:22:49.932 AMForcepoint CSGEmailProductivity Loss0AcceptedAccepted1Returned mail: see transcript for details127.0.0.11CSG EMail3FrfIXxQKBKsRZZRWPLWPced-YZcPaWjRZZRWP.NZXUOZPWLMdP.Pf@alerts.bounces.google.comNone"None0Mail Delivery SubsystemMAILER-DAEMON@rly01a.srv.mailcontrol.com0Spam Score102814Message SizeNoneBlack/white listedNoneVirus NameDEFAULTPolicy NameNoneAdvanced Encryption2020-12-10T10:16:11.000ZLog Created Time CleanFiltering ReasonCommonSecurityLog