Field type |
Field name |
Description |
Example value |
---|---|---|---|
CEF header |
CEF:Version |
CEF version. |
CEF:0 |
Device Vendor |
Product vendor. |
UserGate |
|
Device Product |
Product type. |
NGFW |
|
Device Version |
Product version. |
7 |
|
Source |
Log name. |
scada |
|
Name |
Source type. |
log |
|
PDU Severity |
SCADA severity. |
Available values:
|
|
CEF [extension] |
rt |
Time when the event was received (in milliseconds since January 1, 1970). |
1652344423822 |
deviceExternalId |
A unique name of the device which generated the event. |
||
act |
Action taken by the device according to the configured policies. |
accept |
|
cs1Label |
Indicates that a rule was triggered. |
Rule |
|
cs1 |
Name of the rule triggered to cause the event. |
Scada Rule Example |
|
src |
Traffic source IPv4 address. |
10.10.10.10 |
|
spt |
Source port. |
Values: 0-65535. |
|
cs2Label |
Indicates the source zone. |
Source Zone |
|
cs2 |
Source zone name. |
Trusted |
|
cs3Label |
Indicates the source country. |
Source Country |
|
cs3 |
Source country name. |
AE (a two-letter country code is displayed) |
|
dst |
IPv4 address of the traffic destination. |
194.226.127.130 |
|
dpt |
Destination port. |
Values: 0-65535. |
|
cs4Label |
Indicates the destination zone. |
Destination Zone |
|
cs4 |
Destination zone name. |
Untrusted |
|
cs5Label |
Indicates the destination country. |
Destination Country |
|
cs5 |
Destination country name. |
AE (a two-letter country code is displayed) |
|
app |
Application layer protocol. |
Modbus |
|
cs6Label |
Refers to the device information. |
PDU Details |
|
cs6 |
Device details in JSON format. |
{"protocol":"modbus","pdu_severity":0,"pdu_func":"3","pdu_address":0, "mb_value":0,"mb_quantity":0,"mb_payload":"AAIAAA==", "mb_message":"response","mb_addr":0} |