Security messages in CEF format consists of the body and a header.
You cannot change the format of CEF messages by adding, modifying, or removing fields.
The header of each event has seven required fields, separated by | characters:
CEF:0. Corresponding field in KUMA: Extra Kaspersky. Corresponding field in KUMA: DeviceVendor.Kaspersky NGFW. Corresponding field in KUMA: DeviceProduct.DeviceVersion.DeviceEventClassID.Possible values:
FirewallDNS SecurityWeb ControlSSL InspectionURL AntivirusFile Anti-VirusIDPSExplicit ProxyServiceAuthentication Event, Account management, Traffic filtering management, IP address settings, MAC address settings, General functions settings, Security functions management, Journal managementSettings modifiedName.Possible values:
Firewall:Session startSession endDetectDetectExclusionDecryption errorExclusionDetectExclusionDetectExclusionDetectRules scheduleCertKSNDBConnectionSuccessful AuthenticationUser Account ModifiedSecurity RuleIP addressMAC addressDecryption ruleLogging settingsSeverity. Not used, the value of the field is Unknown.In some logs, the severity is indicated in the Priority field.
SpaceID.Possible values:
Management eventsSystem eventsDataplane eventsService eventsExample: CEF:0|Kaspersky|Kaspersky NGFW|1.1.0.0|Firewall|Session start|Unknown |
All fields of the CEF message body have the <key>=<value> format. If a key has multiple values, these values are separated by commas. Colons separate keys.
Keys and values contained in a message depend on the type of event.
For more information about the data model of the normalized event in KUMA, see the KUMA Help.
In the session log for ICMP traffic, the spc and dpt keys show the ICMP ID value.