Logo
Sign in
  1. Logpoint Service Desk
  2. Products Hub
  3. Marketplace
default.png

CEF Normalizer

The CEF Compiled Normalizer normalizes the CEF event logs in CEF format from various log sources.  

For Logpoint version:

6.7.0 or later 6.0.0 to 6.6.6
Release Details
Version:5.0.1
Release date:2020-05-14
Document date:2020-05-14
SHA 256: 83a842f106a2432f8b37bbc482ca10a6870980ef159040666dbccea280b62368
Download

Package Details

The application consists of the following component:

  1. Compiled Normalizer
    • CEFCompiledNormalizer

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

Installation

Follow these steps to install the CEF Compiled Normalizer v5.0.1 application:

  1. Download the CEF Compiled Normalizer package from the Download section above.
  2. Add the required device in LogPoint.
  3. Create a normalization policy, and add the required CEFCompiledNormalizer package.
  4. Create a collection policy with the Syslog collector and appropriate processing policy. 
  5. Assign the log collection policy to the device.

Supported Devices

The supported devices with LogPoint in this configuration are:

  • Trend Micro Deep Security CEF
  • Rhebo CEF
  • Malwarebytes CEF
  • Trend Micro Deep Discovery CEF
  • FireEye CEF
  • ForeScout CEF
  • PaloAlto CEF
  • SentinelOne CEF
  • RedSocks CEF
  • Any device with CEF format

Configuration of Sources

Expected Log Format

CEF:Version|Device Vendor|Device Product|Device Version|Device Event Class ID|Name|Severity|[Extension]

Please note that the Extension field in the aforementioned log format is optional. 

Log Sample

Jan 20 2020 15:19:10 Win7 CEF:0|Malwarebytes|Malwarebytes Breach Remediation|2.7.1.1627 [eng:v1.1.11.1 rul:v1111.11.11.11 act:v111.11.11.11 sws:v2016.11.11.11]|1001|Malware Detected|10|cs3=1a111111-1111-111a-b61e-62f34b947584 cs3Label=SessionId cs5="C:\\mbbr\\mbbr.exe" scan -threat -remove -noreboot -noarchive -ignorepu -ark -pfi:1 -stdout:summary -stdlog:C:\\mbbr\\logs\\scanResults-WIN7-20161220-031802.xml  cs5Label=CmdLine dvchost=Win8 deviceMacAddress=00:00:XX:XX:XX:XX suser=SYSTEM outcome=failed rt=Dec 20 2016 15:19:10 cs1Label=MalwareName cs2Label=MalwareHash cs4Label=MalwareClass cs1=Trojan-xxxx cs2=702644a56a30c76fcc1f4e2b30d105fb cs4=1 filePath=C:\\temp\\aaaAAAAaAAaa.exe act=none cat=virus

Release Details
Version:3.4.0
Release date:2020-05-14
Document date:2020-05-14
SHA 256: 5aad561c036caf8af558190d48f01b73b387d8ae33076a799d095ba4b7946397
Download

Package Details

The application consists of the following component:

  1. Compiled Normalizer
    • CEFCompiledNormalizer

Enhancement

A minor update has been done in the application’s normalizer for better signature handling. 

Installation

Follow these steps to install the CEF Compiled Normalizer v3.4.0 application:

  1. Download the CEF Compiled Normalizer package from the Download section above.
  2. Add the required device in LogPoint.
  3. Create a normalization policy, and add the required CEFCompiledNormalizer package.
  4. Create a collection policy with the Syslog collector and appropriate processing policy. 
  5. Assign the log collection policy to the device.

Supported Devices

The supported devices with LogPoint in this configuration are:

  • Trend Micro Deep Security CEF
  • Rhebo CEF
  • Malwarebytes CEF
  • Trend Micro Deep Discovery CEF
  • FireEye CEF
  • ForeScout CEF
  • PaloAlto CEF
  • SentinelOne CEF
  • RedSocks CEF
  • Any device with CEF format

Configuration of Sources

Expected Log Format

CEF:Version|Device Vendor|Device Product|Device Version|Device Event Class ID|Name|Severity|[Extension]

Please note that the Extension field in the aforementioned log format is optional. 

Log Sample

Jan 20 2020 15:19:10 Win7 CEF:0|Malwarebytes|Malwarebytes Breach Remediation|2.7.1.1627 [eng:v1.1.11.1 rul:v1111.11.11.11 act:v111.11.11.11 sws:v2016.11.11.11]|1001|Malware Detected|10|cs3=1a111111-1111-111a-b61e-62f34b947584 cs3Label=SessionId cs5="C:\\mbbr\\mbbr.exe" scan -threat -remove -noreboot -noarchive -ignorepu -ark -pfi:1 -stdout:summary -stdlog:C:\\mbbr\\logs\\scanResults-WIN7-20161220-031802.xml  cs5Label=CmdLine dvchost=Win8 deviceMacAddress=00:00:XX:XX:XX:XX suser=SYSTEM outcome=failed rt=Dec 20 2016 15:19:10 cs1Label=MalwareName cs2Label=MalwareHash cs4Label=MalwareClass cs1=Trojan-xxxx cs2=702644a56a30c76fcc1f4e2b30d105fb cs4=1 filePath=C:\\temp\\aaaAAAAaAAaa.exe act=none cat=virus

Support

If you have any queries or require assistance, please feel free to contact our support team: 

Email: servicedesk@logpoint.com
Phone: +45 7060 6100

Best regards,
untitled.svg

Comments

Article is closed for comments.

Follow

Related articles

  • Palo Alto Network Firewall
  • Universal Normalizer
  • Office365
  • Windows
  • Trend Micro
Privacy policy    EULA    Terms of service   
Copyright © , Logpoint. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.