ESET PROTECT – Table of Contents

Events exported to LEEF format

To filter the event logs sent to Syslog, create a log category notification with a defined filter.

LEEF format is a customized event format for IBM® Security QRadar®. Events have standard and custom attributes:

ESET PROTECT uses some of standard attributes described in official IBM documentation.

Custom attributes are the same as in JSON format. The deviceGroupName attribute contains the full path to the static group of the computer generating the event. If the path is longer than 255 characters, deviceGroupName contains only the static group name. The deviceOSName attribute contains information about the computer´s operating system, and the deviceGroupDescription attribute contains the static group description.

Event categories:

Antivirus detectionsAntivirus detections

arrow_down_businessThreat event example

 

Firewall detections Firewall

arrow_down_businessFirewall event example

 

Filtered websites—Web Protection detections Web Protection

arrow_down_businessFiltered websites event example

 

HIPS detections HIPS

arrow_down_businessHIPS event example

 

Audit

ESET Inspect alerts ESET Inspect Alerts

arrow_down_businessESET Inspect Alerts event example

 

Blocked files Blocked files

arrow_down_businessBlocked files event example

Incidents

arrow_down_businessIncidents Integration Event

 


Note

You can find more information about Log Event Extended Format (LEEF) on the official IBM website.