17.1.10. Endpoint hardware log format

Field type

Field name

Description

Example value

CEF header

CEF:Version

CEF version.

CEF:0

Device Vendor

Product vendor.

UserGate

Device Product

Product type.

NGFW

Device Version

Product version.

7

Source

Log type.

endpoint_hardware

Name

Source type.

log

Threat Level

Default value.

0

CEF [extension]

rt

Time when the event was received (in milliseconds since January 1, 1970).

1652344423822

deviceExternalId

A unique name of the device which generated the event.

35fb5820-74db-4eac-b05b-d01bc284c4e8

act

Action (add/remove the device).

add_device, remove_device

cs1Label

Indicates the endpoint ID.

endpointId

cs1

Endpoint ID.

35fb5820-74db-4eac-b05b-d01bc284c4e8

cs2Label

Indicates the endpoint name.

endpointName

cs2

Endpoint NetBIOS name.

DESKTOP-0731NFQ

sourceServiceName

Windows driver used for working with the device.

USBHUB3

cs3Label

Indicates the ID of device added/removed.

deviceId

cs3

Device ID.

USB\\VID_0E0F&PID_0002\\6&201153C1&0&8

cs4Label

Indicates the device name.

deviceName

cs4

Device name.

Kingston DataTraveler 2.0 USB Device