Jump to navigation

  • English
  • Русский
Home
  • Resources

      • Document Library
      • Video
      • Changes in UserGate 5
      • Changes in UserGate 6
      • Changes in UserGate Management Center 6
      • Changes in UserGate Log Analyzer 6
      • Changes in UserGate 7
      • Changes in UserGate Management Center 7
      • Changes in UserGate Log Analyzer 7
      • Changes in UserGate SIEM 7
      • Changes in UserGate WAF 7

      • L7 Applications
      • Categories
  • Support service
    • Add a Ticket
    • Download
    • Demo Online
  • Lifecycle

You are here

Home > Support Portal > Documentation > UserGate Log Analyzer 7 > 17.1. Logs Export in CEF Format

Search form

  • 1. Introduction
  • 2. UserGate LogAn Licensing
  • 3. Initial Configuration
    • 3.1. HSC Deployment
    • 3.2. Virtual Appliance Deployment
    • 3.3. Connecting to UserGate LogAn
  • 4. UserGate LogAn Configuration
    • 4.1. General Settings Section
    • 4.2. Device management
      • 4.2.1. Diagnostics
      • 4.2.2. Server operations
      • 4.2.3. System backup management
      • 4.2.4. Settings export and import
    • 4.3. Administrators
    • 4.4. Certificate Management
    • 4.5. Auth servers
      • 4.5.1. LDAP Connector
      • 4.5.2. RADIUS Authentication Server
      • 4.5.3. TACACS+ Authentication Server
    • 4.6. Authentication Profiles
    • 4.7. User Roles and Role Permissions
  • 5. Offline Server Operations
  • 6. Network Configuration
    • 6.1. Zone Configuration
    • 6.2. Network Interface Configuration
      • 6.2.1. Bonding Network Interfaces
    • 6.3. Gateway Configuration
    • 6.4. Routes
  • 7. Command Line Interface (CLI)
  • 8. Sensors
    • 8.1. UserGate Sensors
    • 8.2. SNMP Sensors
    • 8.3. SNMP MIB Management
    • 8.4. WMI Sensors
    • 8.5. Endpoint Devices
    • 8.6. Connectors
  • 9. Log collector
    • 9.1. Syslog
  • 10. Libraries
    • 10.1. Emails
    • 10.2. Phones
    • 10.3. Commands
    • 10.4. Notification Profiles
    • 10.5. Triggered Alert Categories
    • 10.6. External Enrichment Services
    • 10.7. Syslog Applications
  • 11. Dashboard
  • 12. Logs and Reports
    • 12.1. Logs
      • 12.1.1. Event Log
      • 12.1.2. Web Access Log
      • 12.1.3. Traffic Log
      • 12.1.4. IDPS Log
      • 12.1.5. SCADA Log
      • 12.1.6. SSH Inspection Log
      • 12.1.7. Search History
      • 12.1.8. Endpoint Event Log
      • 12.1.9. Endpoint Rule Log
      • 12.1.10. Endpoint Application Log
      • 12.1.11. Endpoint Hardware Log
      • 12.1.12. System Log
      • 12.1.13. Data Search and Filtering
      • 12.1.14. Logs Export
    • 12.2. Reports
      • 12.2.1. Templates
      • 12.2.2. Custom Report Templates
      • 12.2.3. Report Rules
      • 12.2.4. Generated reports
    • 12.3. Incident Reports
      • 12.3.1. Incident Report Templates
      • 12.3.2. Incident Report Rules
      • 12.3.3. Generated Incident Reports
  • 13. Analytics
    • 13.1. Example of Analytics Rule Configuration
    • 13.2. Analytics Search
    • 13.3. Response Actions
      • 13.3.1. Send Email Action
      • 13.3.2. Send Message Action
      • 13.3.3. Webhook Action
      • 13.3.4. Send Command to Connector Action
      • 13.3.5. Send Command to Endpoint Action
      • 13.3.6. Alert Template
    • 13.4. Triggered Alerts
    • 13.5. Triggered Alert Details
    • 13.6. Endpoint Processes
  • 14. Incidents
    • 14.1. Incident Settings
    • 14.2. Incident Dashboard
    • 14.3. Incidents Log
    • 14.4. Creating Security Incidents
    • 14.5. Incident Details
  • 15. Support
  • 16. Appendix 1. Network Environment Requirements
  • 17. Appendix 2. Description of Log Formats
    • 17.1. Logs Export in CEF Format
      • 17.1.1. Event Log Format
      • 17.1.2. Web access log format
      • 17.1.3. Traffic log format
      • 17.1.4. IDPS log format
      • 17.1.5. SCADA log format
      • 17.1.6. SSH inspection log format
      • 17.1.7. Endpoint events log format
      • 17.1.8. Endpoint rules log format
      • 17.1.9. Endpoint applications log format
      • 17.1.10. Endpoint hardware log format
    • 17.2. Export logs in JSON format
      • 17.2.1. Event log description
      • 17.2.2. Web access log description
      • 17.2.3. Traffic log description
      • 17.2.4. IDPS log description
      • 17.2.5. SCADA log description
      • 17.2.6. SSH inspection log description
      • 17.2.7. Endpoint events log description
      • 17.2.8. Endpoint rules log description
      • 17.2.9. Endpoint applications log description
      • 17.2.10. Endpoint hardware log description

17.1. Logs Export in CEF Format

  • 17.1.1. Event Log Format
  • 17.1.2. Web access log format
  • 17.1.3. Traffic log format
  • 17.1.4. IDPS log format
  • 17.1.5. SCADA log format
  • 17.1.6. SSH inspection log format
  • 17.1.7. Endpoint events log format
  • 17.1.8. Endpoint rules log format
  • 17.1.9. Endpoint applications log format
  • 17.1.10. Endpoint hardware log format
‹ 17. Appendix 2. Description of Log Formats up 17.1.1. Event Log Format ›
Terms of Use|Privacy Policy

Copyright © 2001-2025 UserGate